Back to the register
TCPA · Compliance checklist · Updated 2026-07-19

The definitive TCPA compliance checklist for eCommerce & SaaS in 2026.

Every SMS marketing program that touches U.S. consumers operates under the Telephone Consumer Protection Act. Violations carry statutory damages of $500–$1,500 per message. Use this checklist as an operator-focused reference — pair it with counsel for anything customer-specific.

2. Honor revocation immediately

Recipients can revoke consent by any reasonable means. Under 2025 FCC rulemaking, revocation must be honored within 10 business days and cannot be limited to a single keyword.

  • Accept STOP + reasonable variants

    Accept STOP, END, CANCEL, UNSUBSCRIBE, QUIT — plus free-form revocation (e.g. 'please stop texting me'). Do not require an exact keyword.

  • One confirmation only

    You may send one confirmation SMS after opt-out. Any further marketing message is a per-violation risk.

  • Suppress across programs

    A STOP on one campaign must suppress the number across all marketing programs unless the recipient explicitly opted into multiple, separately consented programs.

  • 10 business day cap

    Log the revocation timestamp and confirm your ESP applies suppression well inside the 10-business-day window.

3. Respect quiet hours and calling windows

  • 8am – 9pm local time

    Marketing calls and texts must land between 8:00am and 9:00pm in the recipient's local time zone.

  • Time zone by area code

    Determine the local time from the recipient's stated address; fall back to area code only when address is unknown.

  • State-level windows

    Several states (FL, OK, WA) restrict windows further. Confirm your ESP supports per-state quiet hours.

4. Maintain audit-ready records

In TCPA litigation, the defendant carries the burden of proving consent. Records must survive four years — the federal TCPA statute of limitations.

  • Immutable consent log

    Store consent events append-only. Include: phone number, timestamp, IP, user agent, exact disclosure text version, source URL, campaign, and the double opt-in confirmation (when used).

  • Revocation log

    Log every STOP and free-form revocation the same way. Include the channel it arrived on.

  • Retention

    Keep consent and revocation evidence for at least four years after the last message sent.

  • Vendor changes

    When you switch ESPs, migrate consent evidence, not just phone numbers.

5. Use double opt-in for high-risk surfaces

  • Checkout SMS boxes

    Checkout and lead magnet forms are the highest-litigated opt-in surfaces. A confirmation reply loop mitigates disputed consent claims.

  • Purchased and enriched data

    Do not send marketing SMS to numbers you did not collect directly with express written consent — even if a data broker labels them opt-in.

6. Sync with DNC and reassigned-number checks

  • National DNC

    Marketing calls (including autodialed) must scrub against the National Do-Not-Call Registry every 31 days.

  • Internal DNC

    Maintain an internal DNC list for anyone who has revoked consent from your company.

  • Reassigned Numbers Database

    Check the FCC Reassigned Numbers Database before dialing older opt-ins. A safe-harbor defense exists only when you can prove the query.

7. Operationalize continuous monitoring

  • Version your disclosures

    Every disclosure text change is a new consent version. Tie each opt-in event to the version live at the moment of collection.

  • Audit forms on every release

    Regressions on checkout forms (a re-added default-check, a missing frequency line) are the most common source of new TCPA exposure. Scan on every deploy.

  • Board-visible risk score

    Track TCPA-specific risk alongside GDPR, WCAG, and CCPA in one exec view so remediation actually gets prioritized.

Run this checklist against your live site.

ConsentTensor runs every item above continuously — form disclosures, revocation handling, quiet-hour configuration, and record-keeping evidence — with alerts the moment something regresses.

Run a free scan

This checklist provides compliance guidance for informational purposes and is not legal advice. Consult qualified counsel for jurisdiction-specific questions.