Back to the register
TCPA · Compliance checklist · Updated 2026-07-19

The definitive TCPA compliance checklist for eCommerce & SaaS in 2026.

Every SMS marketing program that touches U.S. consumers operates under the Telephone Consumer Protection Act. Violations carry statutory damages of $500–$1,500 per message — enough to turn a single non-compliant blast into a seven-figure class action. Use this checklist as an operator-focused reference; pair it with counsel for anything customer-specific.

Abstract illustration of SMS message bubbles converging on a compliance shield
$500 – $1,500
statutory damages per violating message
4 years
federal statute of limitations
10 days
to honor revocation (2025 FCC rule)
Key takeaways
  • Consent must be prior, express, written, and unbundled — pre-checked boxes are the #1 defect.
  • Under the 2025 FCC rule, any reasonable revocation ends consent across every marketing program within 10 business days.
  • You must keep audit-ready consent evidence for four years — the burden of proof is on the sender.
  • Quiet hours (8am–9pm local) apply per recipient time zone, not sender time zone.

2. Honor revocation immediately

Recipients can revoke consent by any reasonable means. Under 2025 FCC rulemaking, revocation must be honored within 10 business days and cannot be limited to a single keyword.

  • Accept STOP + reasonable variants

    Accept STOP, END, CANCEL, UNSUBSCRIBE, QUIT — plus free-form revocation (e.g. 'please stop texting me'). Do not require an exact keyword.

  • One confirmation only

    You may send one confirmation SMS after opt-out. Any further marketing message is a per-violation risk.

  • Suppress across programs

    A STOP on one campaign must suppress the number across all marketing programs unless the recipient explicitly opted into multiple, separately consented programs.

  • 10 business day cap

    Log the revocation timestamp and confirm your ESP applies suppression well inside the 10-business-day window.

3. Respect quiet hours and calling windows

  • 8am – 9pm local time

    Marketing calls and texts must land between 8:00am and 9:00pm in the recipient's local time zone.

  • Time zone by area code

    Determine the local time from the recipient's stated address; fall back to area code only when address is unknown.

  • State-level windows

    Several states (FL, OK, WA) restrict windows further. Confirm your ESP supports per-state quiet hours.

4. Maintain audit-ready records

In TCPA litigation, the defendant carries the burden of proving consent. Records must survive four years — the federal TCPA statute of limitations.

  • Immutable consent log

    Store consent events append-only. Include: phone number, timestamp, IP, user agent, exact disclosure text version, source URL, campaign, and the double opt-in confirmation (when used).

  • Revocation log

    Log every STOP and free-form revocation the same way. Include the channel it arrived on.

  • Retention

    Keep consent and revocation evidence for at least four years after the last message sent.

  • Vendor changes

    When you switch ESPs, migrate consent evidence, not just phone numbers.

5. Use double opt-in for high-risk surfaces

  • Checkout SMS boxes

    Checkout and lead magnet forms are the highest-litigated opt-in surfaces. A confirmation reply loop mitigates disputed consent claims.

  • Purchased and enriched data

    Do not send marketing SMS to numbers you did not collect directly with express written consent — even if a data broker labels them opt-in.

6. Sync with DNC and reassigned-number checks

  • National DNC

    Marketing calls (including autodialed) must scrub against the National Do-Not-Call Registry every 31 days.

  • Internal DNC

    Maintain an internal DNC list for anyone who has revoked consent from your company.

  • Reassigned Numbers Database

    Check the FCC Reassigned Numbers Database before dialing older opt-ins. A safe-harbor defense exists only when you can prove the query.

7. Operationalize continuous monitoring

  • Version your disclosures

    Every disclosure text change is a new consent version. Tie each opt-in event to the version live at the moment of collection.

  • Audit forms on every release

    Regressions on checkout forms (a re-added default-check, a missing frequency line) are the most common source of new TCPA exposure. Scan on every deploy.

  • Board-visible risk score

    Track TCPA-specific risk alongside GDPR, WCAG, and CCPA in one exec view so remediation actually gets prioritized.

Common defects we see in the wild

Across thousands of ConsentTensor scans, five defects account for the majority of open TCPA exposure. Fixing these takes hours, not weeks.

  1. 1Pre-checked SMS opt-in at checkout — plaintiff-firm bait, and disqualifies the consent entirely.
  2. 2Missing message-frequency disclosure (e.g. no 'up to 8 msgs/mo' line near the opt-in).
  3. 3STOP handling limited to a single exact keyword instead of accepting reasonable variants and free-form language.
  4. 4No versioning on the disclosure text — impossible to prove what a user agreed to on a given date.
  5. 5Marketing sends outside 8am–9pm in the recipient's time zone due to ESP defaults set to sender time zone.

Frequently asked questions

Does TCPA apply to transactional messages?+

Order confirmations, shipping updates, and 2FA fall outside the marketing consent standard — but only if they contain zero promotional content. A shipping SMS that tacks on a discount code converts it into a marketing message and requires prior express written consent.

Do we need double opt-in?+

The TCPA does not require it, but double opt-in is the single strongest litigation defense. It also produces a clean, timestamped confirmation record you can hand to opposing counsel.

What about purchased or enriched phone lists?+

Do not send marketing SMS to numbers you did not collect directly with express written consent. Broker-labeled 'opt-in' data is a leading source of class-action exposure.

How long do we need to keep consent records?+

At least four years after the last message sent — matching the federal TCPA statute of limitations. Some state analogs (like FTSA in Florida) reach further; retain seven years to be safe.

Run this checklist against your live site.

ConsentTensor runs every item above continuously — form disclosures, revocation handling, quiet-hour configuration, and record-keeping evidence — with alerts the moment something regresses.

This checklist provides compliance guidance for informational purposes and is not legal advice. Consult qualified counsel for jurisdiction-specific questions.