TCPA violations occur when an organization calls or texts people without the required consent, ignores opt-out requests, contacts numbers on the Do Not Call Registry, or sends messages outside permitted hours. The penalties are statutory: $500 per violation and up to $1,500 per willful or knowing violation, with each message counting separately. Because damages multiply across every recipient on a list, a single bad campaign can create exposure far beyond what most teams expect.

This article is general information, not legal advice. Talk to an attorney about your specific situation.

Key takeaways:

  • The most common TCPA violations are texting without consent, continuing after an opt-out, quiet-hour violations, and calling Do Not Call Registry numbers.
  • Damages are set by statute at $500 per violation, rising to $1,500 when the violation is willful or knowing, with no cap.
  • Each message is a separate violation, so exposure multiplies across your list and across every send.
  • Plaintiffs do not need to prove they were harmed, which makes TCPA claims attractive to class action attorneys.
  • Prevention is operational: documented opt-ins, instant opt-out suppression, recipient-local scheduling, and regular list hygiene.

The most common TCPA violations

Most organizations that violate the TCPA are not bad actors. They are teams running outreach programs without understanding where the tripwires sit. The violations that generate the most claims fall into four buckets:

  • No consent, or the wrong tier of consent. Sending automated texts to people who never opted in, or sending marketing and fundraising messages to people who only gave informational consent. Purchased and rented lists are the classic version of this violation.
  • Ignoring opt-outs. Continuing to text someone after they replied STOP, or after they revoked consent by email, phone call, or any other reasonable means. Under the FCC rule effective in 2025, revocations must be honored within 10 business days at the latest.
  • Quiet-hour violations. Sending telemarketing messages before 8 a.m. or after 9 p.m. in the recipient's local time zone. National campaigns scheduled on the sender's clock violate this constantly.
  • Do Not Call Registry violations. Placing telemarketing calls or texts to numbers on the National Do Not Call Registry without an applicable exception such as established consent. The registry is managed by the FTC; details are at https://www.ftc.gov/.

A fifth category deserves mention: reassigned numbers. Mobile carriers recycle phone numbers. If your consented contact abandons a number and a stranger inherits it, your next text goes to someone who never opted in. Courts have found liability in exactly this scenario, which is why stale lists are dangerous even when the original consent was perfect.

How the statutory damages math works

The TCPA, at 47 U.S.C. 227, creates a private right of action with fixed statutory damages:

  • $500 per violation for ordinary violations.
  • Up to $1,500 per violation when a court finds the violation willful or knowing.

Three features make these numbers more dangerous than they first appear.

Each message is a separate violation

Damages do not attach per person or per campaign. They attach per message. Text the same non-consenting person once a week for a year, and you are looking at dozens of separate violations from a single contact.

No proof of harm required

A plaintiff does not need to show financial loss, distress, or any injury beyond receiving the message. The statute sets the damages, which removes the hardest part of most lawsuits and makes these claims cheap to bring.

The multiplication problem

The real exposure comes from scale. Consider what happens when a violation runs across a list instead of a single recipient:

ScenarioMessages at issueExposure at $500 eachExposure at $1,500 each
One person, one message1$500$1,500
One person, weekly texts for a year52$26,000$78,000
1,000-contact list, one non-consented blast1,000$500,000$1,500,000
1,000-contact list, four blasts4,000$2,000,000$6,000,000

These figures are simple statutory arithmetic, not predictions about what any case would settle for. But they explain why organizations rarely litigate weak positions to judgment and why class actions in this space produce substantial settlements. The federal statute of limitations lets claims reach back four years, so the arithmetic can cover years of sends, not just last month's.

FCC enforcement vs private lawsuits

TCPA penalties arrive through two separate doors, and they work differently.

FCC enforcement. The Federal Communications Commission can investigate robocall and robotext operations, issue citations, and impose forfeitures. FCC actions tend to target large-scale or fraudulent operations, and the agency also pressures carriers to block illegal traffic. Guidance and enforcement news live at https://www.fcc.gov/robocalls.

Private right of action. Any recipient of a violating call or text can sue directly, individually or on behalf of a class. This is where the realistic risk sits for nonprofits, healthcare organizations, schools, and agencies. Plaintiff firms actively advertise for people who received unwanted texts, and demand letters frequently arrive before any lawsuit is filed.

For a mission-driven organization, even a claim you would ultimately win is expensive: legal fees, staff time, and the reputational sting of a supporter or patient suing you over your own outreach.

How organizations violate the TCPA by accident

Almost every TCPA claim against a legitimate organization traces to an operational gap rather than an intent to spam:

  • A volunteer uploads an old spreadsheet of contacts whose consent status nobody can verify.
  • The opt-out list from a previous texting vendor never gets migrated to the new one.
  • STOP replies land in an inbox nobody monitors, so the numbers stay active.
  • A fundraising appeal goes to a list that only consented to service updates.
  • A national send is scheduled for 7 p.m. Eastern, which is 4 p.m. Pacific but delivers to a stray timezone edge case at the wrong hour after a delay, or worse, is scheduled at 9:30 p.m. sender time without a local-time check.
  • Someone revokes consent on a phone call, the note stays in the CRM, and the texting platform never hears about it.

Notice the pattern: every one of these is a systems failure. Consent lived in one place, suppression lived in another, and nothing connected them. This is why platform choice matters as much as policy. FRANSiS, for example, processes STOP replies automatically and suppresses opted-out contacts across campaigns, so an unmonitored inbox cannot turn into a lawsuit.

Your prevention checklist

Run through this list quarterly. Every item maps to a violation category above.

  1. Verify consent for every contact. If you cannot document when, where, and how a number opted in, do not text it. Never purchase or rent lists.
  2. Use written consent language for marketing and fundraising. Include program name, message frequency, "message and data rates may apply," and HELP/STOP instructions at opt-in.
  3. Automate opt-out handling. STOP, and reasonable variants, should suppress a contact instantly and globally, not per campaign. Honor revocations made by any reasonable means.
  4. Migrate suppression lists when you switch vendors. The opt-out list is the first thing to move, before any contacts.
  5. Schedule by recipient local time. Keep all telemarketing sends between 8 a.m. and 9 p.m. where the recipient lives.
  6. Scrub against the Do Not Call Registry where your messages qualify as telemarketing.
  7. Refresh stale lists. Reconfirm or drop contacts who have been inactive for an extended period, since numbers get reassigned.
  8. Keep records for at least four years, matching the federal statute of limitations.
  9. Train everyone who touches the list, including volunteers and seasonal staff.

For a deeper, printable version, work through our TCPA compliance checklist for 2026 alongside the broader SMS compliance checklist that covers carrier and 10DLC requirements too.

Frequently asked questions

What is the fine for a TCPA violation?

The statute sets damages at $500 per violation, and up to $1,500 per violation when the conduct is willful or knowing. Each message can count as a separate violation, and there is no cap on total damages, so exposure scales with list size and send frequency.

Can individuals sue for TCPA violations?

Yes. The TCPA includes a private right of action, meaning any person who receives a violating call or text can sue directly in court, without waiting for the FCC to act. They do not need to prove actual harm, and they can sue individually or as part of a class action.

What counts as a willful TCPA violation?

Courts generally treat a violation as willful or knowing when the sender knew the facts that made the conduct unlawful, such as continuing to text after receiving a STOP reply. Willfulness raises potential damages from $500 to as much as $1,500 per message, which is why ignoring opt-outs is the most expensive mistake available.

How far back can a TCPA lawsuit reach?

Claims are governed by the four-year federal catch-all statute of limitations. A lawsuit filed today can include violating messages sent up to four years earlier, which is why consent and suppression records should be retained at least that long.

Do TCPA penalties apply to nonprofits?

Yes. Nonprofit status provides only narrow carve-outs from certain telemarketing rules, and courts have allowed TCPA suits against charities and churches to proceed. Nonprofits should collect documented consent and honor opt-outs exactly as a business would.

Conclusion

TCPA penalties look frightening because they are designed to be: fixed damages, per-message multiplication, no harm requirement, and a four-year lookback. But the flip side is that the violations are almost entirely preventable. Organizations get sued over operational gaps, not gray areas, and closing those gaps is mostly a matter of consent discipline and the right tooling.

Want texting that has compliance guardrails built in? Contact the FRANSiS team to see how automatic opt-out suppression, consent recordkeeping, and send-time controls help your organization avoid the violations described above.