Support · Legal
Verified RCS · SMS · MMS
Compliance

TCPA Compliance for Business Texting (2026)

What the TCPA requires for business texting in 2026, consent types, the April 2025 revocation rules, the vacated one-to-one rule, penalties, and a compliance checklist.

By SimplyRCS · July 21, 2026 · 10 min read
A person reviewing a document on a phone
Quick answer

The TCPA (Telephone Consumer Protection Act) requires businesses to get the right level of consent before texting consumers, prior express written consent for marketing, prior express consent for informational messages, and to honor opt-outs made "by any reasonable means" within 10 business days. Violations carry statutory damages of $500 to $1,500 per message, with no cap, which is why a single non-compliant campaign can create existential liability.

One important note before anything else: this guide is educational, not legal advice. TCPA rules shift, states layer their own "mini-TCPA" laws on top, and your specific program deserves review by counsel. What follows is the current federal landscape in plain English, so you can have that conversation well-informed.

Why the TCPA matters more than any other messaging rule

Few statutes generate more litigation than the TCPA. It carries statutory damages of $500 to $1,500 per violation with no cap, meaning a single non-compliant text campaign sent to thousands of numbers can produce existential liability, and plaintiff's firms actively hunt for violations. Unlike most compliance topics, this one arrives as a class-action demand letter, not a regulator's warning. The upside: the rules are entirely satisfiable with good process, and the businesses that build consent correctly never think about the TCPA again.

The TCPA distinguishes consent by message type, and getting this distinction right is most of the game:

1. Prior Express Written Consent (PEWC), required for marketing. Any promotional or marketing text requires the consumer's written agreement (electronic signatures and checkbox flows count) that includes a clear disclosure of what they're consenting to, including that they may receive autodialed messages, and that consent is not a condition of purchase. Practically: a compliant opt-in surface (web form, keyword flow, checkout checkbox) with explicit disclosure language, captured and stored with a timestamp.

2. Prior Express Consent, sufficient for transactional/informational messages. For non-marketing messages, order updates, appointment reminders, account alerts, verbal or written consent suffices, provided the consumer's number was shared in a context directly related to the communication (they gave you their number when placing the order, then you text shipping updates). But the moment a message contains promotional content, it needs the written standard, a "your order shipped, and here's 20% off your next one" message is a marketing message.

The provability rule: consent you can't prove functionally doesn't exist. Store who consented, when, how (which surface, what disclosure language they saw), and for what. In litigation, consent provability is the whole game.

What changed in 2025 to 2026 (the current landscape)

The past two years were the most consequential for TCPA rules in a decade. Three things every texting program should know:

The one-to-one consent rule is dead. The FCC's proposed rule, which would have required lead-gen forms to obtain separate consent for each individual brand, was vacated by the Eleventh Circuit in January 2025, and the FCC has since formally moved on, leaving the broader pre-existing framework in place. If you built processes anticipating one-to-one consent, the requirement never took effect, though single-brand consent remains best practice and some state laws are stricter.

The revocation rules are live (April 11, 2025). Consumers can now revoke consent "in any reasonable way that clearly communicates" the request, businesses cannot force an exclusive opt-out method, and revocations must be honored within 10 business days. Reply keywords like STOP, QUIT, END, REVOKE, OPT OUT, CANCEL, and UNSUBSCRIBE are per se reasonable, but so is a plain-language "please stop texting me." One non-marketing confirmation message is permitted, sent within five minutes of the request. Real-time processing is best practice even though 10 business days is the ceiling.

The "revoke-all" rule is delayed to January 31, 2027. The provision that would treat an opt-out from one message type as an opt-out from all messages from that sender on unrelated matters has been extended twice by the FCC, most recently in a January 6, 2026 order pushing the effective date to January 31, 2027 while the Commission reconsiders the rule. Prudent programs are architecting for it anyway, cross-channel opt-out tracking is coming in some form.

Beyond the TCPA: the rest of the stack

Federal TCPA compliance isn't the whole picture. Carrier and CTIA rules govern content and sender registration (see our 10DLC guide), carriers filter unregistered A2P traffic regardless of your TCPA posture. State mini-TCPAs (Florida, Oklahoma, Washington, and a growing list) add quiet-hour restrictions, their own consent standards, and private rights of action, some stricter than federal law. Quiet hours under federal rules restrict marketing texts to 8 AM to 9 PM in the recipient's local time, with some states tighter. A compliant program satisfies all layers, not just the statute.

The compliance checklist

  1. Capture the right consent for the message type, written consent with full disclosures for marketing; contextual express consent for transactional.
  2. Store the proof, who, when, how, what disclosure, per channel. Exportable on demand.
  3. Honor every reasonable opt-out, fast, keywords and plain language alike; 10 business days maximum, real-time in practice; one confirmation message within five minutes, no marketing in it.
  4. Track consent per channel, SMS consent isn't RCS consent isn't voice consent. Suppress sends where channel-level consent is absent.
  5. Respect quiet hours, 8 AM to 9 PM recipient-local federally; check state overlays.
  6. Register your senders, 10DLC/toll-free/short code registration is carrier-mandatory and reinforces your compliance story.
  7. Audit your AI and automation, AI-driven outbound channels need the same consent foundation as any campaign; an AI agent that texts is your program, legally.
  8. Re-review with counsel annually, the 2025 to 2026 whiplash (a vacated rule, a twice-delayed rule) shows how fast this moves.

How platform architecture makes compliance automatic

Here's the practical insight: most TCPA violations aren't malicious, they're process failures. An opt-out that a busy agent missed. A developer's bug that ignored the suppression list. A campaign sent to a list whose consent nobody can document. The fix is architectural: compliance enforced by the platform, beneath the application, where a human mistake or a code bug can't override it.

That's how SimplyRCS is built: STOP, HELP, and opt-out keywords are honored instantly and unconditionally at the platform level, above AI bots, above agents, above your API code. Consent is tracked per channel and checked before every send, with automatic suppression of anyone not opted in on that channel. Every consent event is logged in an audit trail. Opt-in surfaces (keywords, QR codes, web widgets) capture the required disclosures at the moment of consent, with optional double opt-in. The result: your team focuses on the message, and the compliance layer that litigation turns on, provable consent, honored revocation, runs itself. See how consent and compliance work →

If a demand letter arrives: the response posture

Because TCPA enforcement arrives as litigation rather than regulatory warning, every texting business should know the shape of the response before it's needed. This isn't legal advice, it's the operational preparation that makes your counsel's job winnable.

Don't delete anything. The instinct to clean up is the worst possible move; preservation obligations attach quickly, and your consent records are your defense, not your exposure.

Pull the consent record for the complaining number immediately. Who opted in, when, through which surface, seeing which disclosure language, on which channel, and every message sent since, plus any revocation and how fast it was honored. If your platform logs consent events properly, this is a query; if it doesn't, this is the moment you discover why provable consent is the whole game.

Audit whether the complaint generalizes. One demand letter about one number is manageable; the question counsel will ask first is whether the same gap (a mis-captured form, a suppression bug, an imported list) touches thousands of numbers. Your per-channel consent data answers this.

Engage counsel before responding. TCPA plaintiffs' firms are professionalized; so is the defense bar. Early, informed engagement routinely resolves weak claims cheaply, and your documented consent architecture is what makes claims weak.

The prevention lesson: nearly every seven-figure TCPA outcome traces to a systemic gap, consent that was never validly captured, or opt-outs that a process failed to honor, rather than a single stray message. Which is the argument for pushing enforcement into the platform layer: when STOP is honored above all application code and every consent event is logged automatically, the systemic failure modes are engineered out, and the demand letter that does arrive meets a complete evidentiary record.

Since provability decides TCPA outcomes, define your record schema deliberately. For every contact, store: the timestamp of consent; the capture surface (which form, keyword, or checkout flow); the exact disclosure language displayed at that moment (version your disclosures so "what did they see" is answerable years later); the channel scope consented to (SMS vs. RCS vs. voice, tracked separately); and the full revocation history, when they opted out, through what words, and how fast suppression took effect. Retain records for at least the limitations window in your jurisdictions (commonly four years federally, longer under some state laws, confirm with counsel). The test of adequacy is simple: could you produce, for any single phone number, a complete consent narrative in five minutes? Platforms with per-channel consent tracking and automatic audit logging make the answer yes by default.

Frequently asked questions

For marketing or promotional texts: prior express written consent, with clear disclosures (including that consent isn't a condition of purchase), captured and stored. For purely transactional or informational texts (order updates, appointment reminders): prior express consent suffices, typically established when the customer provides their number in a directly related context. When in doubt, use the written standard, and store the proof.

What are the TCPA penalties for texting violations?

Statutory damages of $500 per violation, rising to $1,500 for willful violations, per message, with no cap. A non-compliant campaign to a few thousand numbers can therefore generate seven-figure exposure, which is why the TCPA is among the most heavily litigated consumer statutes.

What counts as a valid opt-out in 2026?

Any reasonable communication that clearly asks you to stop. Reply keywords, STOP, QUIT, END, REVOKE, OPT OUT, CANCEL, UNSUBSCRIBE, are per se reasonable, but so is plain language. You cannot require an exclusive opt-out method, must honor requests within 10 business days (real-time is best practice), and may send one non-marketing confirmation within five minutes.

No. The FCC's one-to-one consent rule was vacated by the Eleventh Circuit in January 2025 before taking effect, and the FCC has since moved on from it. The pre-existing consent framework governs, though obtaining brand-specific consent remains best practice, and some state laws impose their own stricter standards.

What is the "revoke-all" rule and when does it apply?

It's the FCC provision that would treat a revocation made in response to one type of message as an opt-out from all calls and texts from that sender on unrelated matters. Its effective date has been extended to January 31, 2027 while the FCC reconsiders the rule. Forward-looking programs are building cross-channel opt-out tracking now.

Does the TCPA apply to RCS messages?

Treat RCS exactly like SMS for consent purposes: marketing RCS needs written consent, informational RCS needs express consent, and opt-outs must be honored identically. Track consent per channel, a customer's SMS opt-in doesn't automatically cover RCS, which is why per-channel consent tracking, as SimplyRCS implements it, matters.

Can my platform handle TCPA compliance for me?

A platform can't replace legal review of your program, but it can make the operational layer automatic: platform-enforced STOP/HELP handling, per-channel consent tracking with send-time suppression, disclosure-complete opt-in capture, and audit logging. SimplyRCS enforces these beneath the application, so a bug or human miss can't override an opt-out.

‹ All blog posts

Try it free

See verified RCS on your own phone.

Get a free sender ID test, or check your readiness in about two minutes.