The TCPA statute of limitations is four years. Because the Telephone Consumer Protection Act does not contain its own limitations period, courts apply the federal catch-all statute at 28 U.S.C. 1658, which gives plaintiffs four years from the date a claim accrues to file suit. Since each non-compliant call or text is treated as a separate violation with its own clock, a texting program can accumulate years of live, suable claims without anyone noticing.

This article is general information, not legal advice. Consult an attorney about deadlines in any actual dispute.

Key takeaways:

  • TCPA claims are governed by the four-year federal catch-all statute of limitations in 28 U.S.C. 1658.
  • Each message is a separate violation with its own limitations clock, so ongoing campaigns create rolling, overlapping exposure.
  • Some courts apply a discovery rule that can delay the start of the clock until the recipient knew or should have known of the claim.
  • Old contact lists are a liability precisely because the lookback window is long and numbers get reassigned.
  • Consent and opt-out records should be retained for at least four years, and ideally five, to cover the full claim window plus filing lag.

Where the four-year period comes from

The TCPA itself, 47 U.S.C. 227, is silent on how long plaintiffs have to sue. When a federal statute enacted after 1990 creates a cause of action but no limitations period, 28 U.S.C. 1658 fills the gap with a default of four years. Federal courts have consistently applied that four-year period to TCPA claims.

Two practical consequences follow:

  • A lawsuit filed today can reach messages sent up to four years ago.
  • Your compliance posture from several years back, old vendors, old lists, old opt-out handling, is still legally live today.

This is longer than many state consumer-protection limitation periods, which is part of why plaintiffs' attorneys favor federal TCPA claims: the window is generous and the damages, $500 to $1,500 per violation, are fixed by statute. For the full damages picture, see our guide to TCPA violations and penalties.

When the clock starts

A limitations period begins when the claim "accrues." For a TCPA claim, the standard rule is that accrual happens when the violating call or text is sent or received. Simple enough for a single message. But texting programs are not single messages, and that is where the math gets interesting.

Each message is its own violation with its own clock

The TCPA treats every non-compliant message as a separate violation. That means every message starts a separate four-year clock. If your organization texted a non-consenting number monthly for three years, you did not create one aging claim. You created thirty-six claims, the oldest expiring on a rolling basis and the newest still fresh.

The practical effect is that an ongoing violation never fully ages out while it continues. Stopping the conduct starts the final clock; continuing it keeps generating new claims that will remain live for four more years each.

The discovery rule

Some courts apply a discovery rule to TCPA claims, holding that the clock does not start until the plaintiff knew, or reasonably should have known, of the violation. In most texting cases this changes little, because a person obviously knows when they receive a text. But discovery arguments appear in edge cases:

  • Calls that went to voicemail boxes the person rarely checked.
  • Messages where the sender's identity was concealed, delaying the recipient's ability to identify who to sue.
  • Situations where the recipient did not initially know the messages were automated or non-consented.

Courts also recognize tolling doctrines in limited circumstances, such as when a defendant actively concealed its conduct. The safe assumption for a defendant organization: do not count on the clock having started early. Assume the full four-year window is available to every recipient.

Why old lists are a liability

The long lookback period converts stale data into legal risk. Three mechanics drive this.

Reassigned numbers. Carriers recycle mobile numbers. A supporter who genuinely opted in five years ago may have abandoned that number, and its new owner never consented to anything. Every message to the reassigned number is a fresh violation with a fresh four-year clock, and your original consent record does not attach to the new owner.

Unmigrated opt-outs. When organizations switch texting vendors, suppression lists sometimes fail to move. Someone who opted out three years ago and starts receiving messages again has a clean, well-documented claim, and the paper trail of their original STOP makes willfulness, and the higher $1,500 tier, easy to argue.

Forgotten consent origins. Four years is long enough for institutional memory to fail. Staff turn over, CRMs get replaced, and the spreadsheet that recorded how a segment opted in disappears. If a claim arrives and you cannot reconstruct consent, you are defending on faith.

The remedy is unglamorous: audit your list on a regular cycle, reconfirm or remove long-inactive contacts, and treat any segment with undocumented consent as untextable until re-consented.

Record retention: match the claim window

Your records are your defense, so your retention policy should be built around the limitations period. The baseline rule: keep consent and compliance records at least four years, and ideally five, since a message sent on the last day of year one can be the subject of a complaint filed on the last day of year four, with litigation discovery following even later.

What to retain for each contact:

  • Consent capture: date, time, source (web form, keyword, paper form), the exact disclosure language displayed, and the phone number as entered.
  • Consent scope: whether the opt-in covered informational messages, marketing and fundraising, or both.
  • Message logs: what was sent, when, and to which numbers.
  • Opt-out events: every STOP or other revocation, with a timestamp and the date suppression took effect.
  • Vendor records: exports from any previous texting platform, especially suppression lists.

A texting platform should generate most of this automatically. FRANSiS keeps consent records, message logs, and opt-out events tied to each contact, which turns a four-year retention policy from a filing project into a default. If you are building your program's broader documentation habits, our TCPA compliance checklist for 2026 includes a full recordkeeping section.

State law analogs and their own deadlines

The federal TCPA is not the only statute in play. A growing number of states have enacted their own telemarketing and texting laws, often called mini-TCPAs, with Florida, Oklahoma, and Washington among the most active. These matter for limitations analysis in three ways:

  • Different clocks. State statutes carry their own limitations periods, which may be shorter or longer than four years depending on the state and the claim.
  • Different definitions. Some state laws define autodialers more broadly than the post-Duguid federal standard, so conduct that is defensible federally may still violate state law.
  • Stacked claims. Plaintiffs frequently plead federal and state claims together, and a state claim can survive even if the federal one fails.

If you text into states with active mini-TCPA statutes, ask counsel to map the limitations periods that apply to your footprint. For operational purposes, the four-year federal window remains the sensible planning baseline, because it is the longest period most organizations will face and it anchors record retention.

What this means for your program today

Pull the threads together and the statute of limitations dictates a short list of operating rules:

  1. Assume every message you send stays legally actionable for four years.
  2. Keep consent, message, and opt-out records for at least four years, ideally five.
  3. Never delete a suppression list, and always migrate it first when changing vendors.
  4. Re-verify long-dormant contacts before texting them again, because reassignment risk grows with time.
  5. If you discover past non-compliant sends, stopping now starts the final clock; continuing extends your exposure indefinitely.

None of this requires panic. It requires a system that remembers things longer than your staff turnover cycle does.

Frequently asked questions

How long is the statute of limitations for TCPA claims?

Four years. The TCPA has no built-in limitations period, so courts apply the federal catch-all statute, 28 U.S.C. 1658, which allows suit within four years of when the claim accrues, generally when the violating message is sent or received.

Does each text message have its own statute of limitations?

Yes. Each non-compliant message is a separate violation with its own four-year clock. An ongoing campaign creates rolling exposure: older messages age out while newer ones remain fully actionable, and the exposure only begins to close once the sending stops.

Can the TCPA clock start later than the message date?

Sometimes. Some courts apply a discovery rule, delaying accrual until the recipient knew or reasonably should have known of the violation, and tolling can apply where a sender concealed its conduct. Organizations should plan around the full four-year window rather than assuming an early start.

How long should we keep SMS consent records?

At least four years, to match the limitations period, and ideally five to account for filing and discovery lag. Records should include the consent date, source, exact disclosure language, scope of consent, message logs, and every opt-out event with its timestamp.

Do state texting laws have different deadlines?

Yes. State mini-TCPA statutes in states like Florida, Oklahoma, and Washington carry their own limitations periods and sometimes broader definitions than federal law. Plaintiffs often bring federal and state claims together, so multi-state programs should map both sets of deadlines with counsel.

Conclusion

The four-year TCPA statute of limitations means your texting program is always accountable for its last four years, not just its last campaign. The organizations that sleep well are the ones whose consent trails, suppression lists, and message logs would survive a subpoena from any point in that window. Build retention around the claim window, keep opt-outs sacred, and refresh aging lists before they refresh themselves with strangers.

Want recordkeeping that outlasts staff turnover? Contact the FRANSiS team to see how automatic consent logging, opt-out tracking, and message history give your organization a defensible four-year paper trail by default.