The definitive TCPA compliance checklist for eCommerce & SaaS in 2026.
Every SMS marketing program that touches U.S. consumers operates under the Telephone Consumer Protection Act. Violations carry statutory damages of $500–$1,500 per message. Use this checklist as an operator-focused reference — pair it with counsel for anything customer-specific.
1. Capture prior express written consent
For any marketing SMS or autodialed call under the TCPA, you must obtain prior express written consent before the first message goes out.
Standalone opt-in
The SMS opt-in must not be pre-checked or bundled with an unrelated agreement. A single consent form should not cover multiple sellers.
Clear disclosure
State the seller's name, the type of messages (marketing, transactional, recurring), that consent is not a condition of purchase, and that message and data rates may apply.
Message frequency
Disclose the expected message frequency (e.g. up to 8 msgs/month). Vague or missing frequency language is the most common cited defect in TCPA complaints.
Signed record
Retain a timestamped, verifiable record of the consent — form snapshot, IP, user agent, exact disclosure text, and the phone number entered.
2. Honor revocation immediately
Recipients can revoke consent by any reasonable means. Under 2025 FCC rulemaking, revocation must be honored within 10 business days and cannot be limited to a single keyword.
Accept STOP + reasonable variants
Accept STOP, END, CANCEL, UNSUBSCRIBE, QUIT — plus free-form revocation (e.g. 'please stop texting me'). Do not require an exact keyword.
One confirmation only
You may send one confirmation SMS after opt-out. Any further marketing message is a per-violation risk.
Suppress across programs
A STOP on one campaign must suppress the number across all marketing programs unless the recipient explicitly opted into multiple, separately consented programs.
10 business day cap
Log the revocation timestamp and confirm your ESP applies suppression well inside the 10-business-day window.
3. Respect quiet hours and calling windows
8am – 9pm local time
Marketing calls and texts must land between 8:00am and 9:00pm in the recipient's local time zone.
Time zone by area code
Determine the local time from the recipient's stated address; fall back to area code only when address is unknown.
State-level windows
Several states (FL, OK, WA) restrict windows further. Confirm your ESP supports per-state quiet hours.
4. Maintain audit-ready records
In TCPA litigation, the defendant carries the burden of proving consent. Records must survive four years — the federal TCPA statute of limitations.
Immutable consent log
Store consent events append-only. Include: phone number, timestamp, IP, user agent, exact disclosure text version, source URL, campaign, and the double opt-in confirmation (when used).
Revocation log
Log every STOP and free-form revocation the same way. Include the channel it arrived on.
Retention
Keep consent and revocation evidence for at least four years after the last message sent.
Vendor changes
When you switch ESPs, migrate consent evidence, not just phone numbers.
5. Use double opt-in for high-risk surfaces
Checkout SMS boxes
Checkout and lead magnet forms are the highest-litigated opt-in surfaces. A confirmation reply loop mitigates disputed consent claims.
Purchased and enriched data
Do not send marketing SMS to numbers you did not collect directly with express written consent — even if a data broker labels them opt-in.
6. Sync with DNC and reassigned-number checks
National DNC
Marketing calls (including autodialed) must scrub against the National Do-Not-Call Registry every 31 days.
Internal DNC
Maintain an internal DNC list for anyone who has revoked consent from your company.
Reassigned Numbers Database
Check the FCC Reassigned Numbers Database before dialing older opt-ins. A safe-harbor defense exists only when you can prove the query.
7. Operationalize continuous monitoring
Version your disclosures
Every disclosure text change is a new consent version. Tie each opt-in event to the version live at the moment of collection.
Audit forms on every release
Regressions on checkout forms (a re-added default-check, a missing frequency line) are the most common source of new TCPA exposure. Scan on every deploy.
Board-visible risk score
Track TCPA-specific risk alongside GDPR, WCAG, and CCPA in one exec view so remediation actually gets prioritized.
Run this checklist against your live site.
ConsentTensor runs every item above continuously — form disclosures, revocation handling, quiet-hour configuration, and record-keeping evidence — with alerts the moment something regresses.
Run a free scanThis checklist provides compliance guidance for informational purposes and is not legal advice. Consult qualified counsel for jurisdiction-specific questions.