tcpa compliance checklist
TCPA Compliance Checklist for 2026
In 2026, TCPA compliance remains a critical component for organizations that rely on telecommunication for outreach and engagement. The Telephone Consumer Protection Act (TCPA) sets the standards for how organizations can engage with individuals via phone calls and SMS. For mission-driven organizations, the operative rules are 47 U.S.C. 227 and the FCC regulations at 47 CFR 64.1200.
This article is informational and is not legal advice. Confirm current requirements with your own counsel.
Understanding TCPA Basics
The TCPA was enacted in 1991 to address the increasing number of telemarketing calls and the use of automated dialing systems. Its primary goal is to protect consumers from unwanted solicitations and ensure their right to privacy. For organizations, this means obtaining proper consent before making calls or sending text messages. The law applies to any organization that uses automated dialing systems, prerecorded voice messages, or SMS to communicate with consumers, making it relevant across various sectors, including nonprofits, healthcare, education, and government.
Key provisions of the TCPA include restrictions on calling times, the requirement for express written consent for certain types of calls, and the obligation to maintain a do-not-call list. Organizations must also be mindful of the National Do Not Call Registry, which allows individuals to opt-out of telemarketing calls. Understanding these fundamental aspects is crucial for any organization that engages in telephonic communication.
Obtaining and Managing Consent
Consent is the cornerstone of TCPA compliance. Organizations must ensure they have obtained the appropriate level of consent from individuals before initiating any telecommunication. There are two types of consent under TCPA: express consent and express written consent. Express consent is typically required for informational calls and texts, while express written consent is necessary for telemarketing messages.
To manage consent effectively, organizations should implement robust consent management systems. This includes clearly documenting how consent was obtained, providing easy opt-out mechanisms, and regularly updating records to reflect any changes in consent status. Platforms like FRANSiS™ offer TCPA consent tooling that streamlines this process, helping organizations maintain accurate and comprehensive consent records.
Implementing Do-Not-Call Lists
Suppression lists matter, but the federal obligations are narrower than most senders assume. The internal do-not-call list requirement at 47 CFR 64.1200(d) applies to telemarketing calls to residential subscribers, and the national Do Not Call Registry at 47 CFR 64.1200(c)(2) applies only to 'telephone solicitations' - which 47 CFR 64.1200(f) defines as messages encouraging a purchase, rental or investment and expressly excludes calls made by or on behalf of a tax-exempt nonprofit organization. The rule that does bind every SMS sender is 47 CFR 64.1200(a)(10): a recipient may revoke consent by any reasonable method, the sender must honor it within a reasonable time not to exceed ten business days, and the sender may not designate an exclusive means of revocation. Build your suppression list around that.
Organizations should establish clear procedures for adding and removing individuals from their do-not-call lists. This includes training staff on how to handle opt-out requests and ensuring that changes are promptly reflected in the organization's communication systems. Using a platform like FRANSiS™ can help automate and manage these lists, reducing the risk of non-compliance.
Timing and Frequency of Communications
The TCPA imposes restrictions on the timing and frequency of telemarketing communications to prevent consumer harassment. Under 47 CFR 64.1200(c)(1), telephone solicitations to residential subscribers may not be initiated before 8 a.m. or after 9 p.m., local time at the called party's location. Note the scope: 47 CFR 64.1200(f) excludes calls made by or on behalf of a tax-exempt nonprofit organization from the definition of 'telephone solicitation', so the federal window does not by its terms reach nonprofit fundraising texts. Several state mini-TCPA statutes impose narrower windows that do apply, and carriers enforce quiet hours as policy, so 8 a.m. to 9 p.m. in the recipient's local time remains the right operating default. Organizations must also be mindful of the frequency of their communications, ensuring that they do not overwhelm or annoy recipients.
To adhere to these guidelines, organizations should develop a communication strategy that balances engagement with respect for recipients' time and preferences. Scheduling tools and AI-driven platforms like FRANSiS™ can assist in automating message dispatch within permissible hours, while also tracking the frequency of messages sent to each recipient.
Leveraging AI for TCPA Compliance
AI technology can play a significant role in ensuring TCPA compliance, particularly for organizations that manage large volumes of communications. FRANSiS™ provides two-way SMS with an AI Powered Helper that handles routine replies, and consent and opt-out tooling that reduces the manual work of staying inside consent and messaging guidelines. Legal responsibility stays with your organization: under 47 U.S.C. 227(b)(3) liability attaches to the sender, not to the platform.
AI can help identify patterns in communication that may lead to compliance issues, such as excessive messaging or contacting individuals outside of allowed hours. By leveraging AI, organizations can not only enhance their compliance efforts but also improve engagement by providing timely and relevant responses to inquiries.
Training and Educating Staff
Ensuring that all staff members are knowledgeable about TCPA requirements is essential for maintaining compliance. Regular training programs should be conducted to educate employees about the importance of consent, the use of do-not-call lists, and the timing and frequency restrictions imposed by the TCPA.
Training should also cover the use of any technology platforms employed by the organization to manage communications. By equipping staff with the knowledge and tools they need to adhere to TCPA guidelines, organizations can minimize the risk of non-compliance and foster a culture of respect for consumer privacy.
For the same obligations organized as a program rather than a checklist, with each rule cited to its primary source, see the SMS compliance requirements in full.
Monitoring and Auditing Compliance
Regular monitoring and auditing of compliance practices are crucial for identifying potential issues before they become significant problems. Organizations should establish a compliance audit schedule that includes reviewing consent records, do-not-call lists, and communication logs.
Audits should also evaluate the effectiveness of training programs and the use of technology in managing TCPA compliance. By conducting thorough audits, organizations can identify areas for improvement and ensure that their compliance practices remain robust and effective.
The bottom line
Maintaining TCPA compliance is an ongoing process that requires vigilance, education, and the right tools. By understanding the fundamental requirements, obtaining proper consent, managing do-not-call lists, and leveraging technology like FRANSiS™, organizations can effectively navigate the complexities of TCPA compliance. Regular training and audits further support these efforts, ensuring that communication practices are not only compliant but also respectful and effective. As communication technology evolves, staying informed and proactive in compliance efforts is key to successful and ethical engagement with stakeholders.
Frequently Asked Questions
What is express consent under TCPA?
Prior express consent is the standard for autodialed informational or transactional calls and texts to wireless numbers under 47 CFR 64.1200(a)(1). The FCC treats a person who knowingly provides their number for a given purpose as having given it for that purpose. It is distinct from 'prior express written consent', a defined term at 47 CFR 64.1200(f)(9) that requires a signed written agreement with specified disclosures and applies to messages that include an advertisement or constitute telemarketing.
How can organizations manage do-not-call lists effectively?
Organizations should regularly update their internal do-not-call lists and cross-reference them with the National Do Not Call Registry. Automation tools can assist in this process.
Why is training staff important for TCPA compliance?
Training ensures that all employees understand TCPA requirements and know how to use communication tools correctly, reducing the risk of non-compliance.
What role does AI play in TCPA compliance?
AI can automate routine communications, monitor messaging patterns for compliance, and provide timely responses, enhancing both compliance and engagement.
What should be included in a TCPA compliance audit?
Audits should review consent records, do-not-call lists, communication logs, training effectiveness, and technology use to ensure comprehensive compliance.
Related: 10DLC registration guide · HIPAA-compliant texting · FRANSiS™ Open Door.
More guides on this topic
- TCPA Compliance for SMS in 2026: What Every Organization Needs to Know to Avoid Fines
- 10DLC Campaign Rejections: Why They Happen & How to Fix Them
- SMS Deliverability: Why Your Texts Aren't Landing
Related guides: TCPA Class Action Lawsuits: Lessons for Mission Driven Orgs · TCPA Statute of Limitations: How Far Back Claims Can Reach
The reason this checklist matters is the exposure behind it. See what TCPA violation fines and penalties actually look like, and how statutory damages multiply across a list.

