Quick answer: TCPA compliance for text messaging comes down to three obligations: obtain express written consent before sending marketing or automated texts, honor every opt-out request immediately, and keep records that prove both. Nonprofits and healthcare organizations are not exempt, and because the TCPA gives individuals a private right of action, senders face per-message statutory liability that multiplies quickly. Below is the complete 2026 rulebook, a copy-ready TCPA compliance checklist, and the consent rules that changed most recently.
This article is general educational guidance, not legal advice. Consult qualified legal counsel for advice specific to your organization.
What the TCPA is and why it matters in 2026
The Telephone Consumer Protection Act (TCPA) is a federal law that governs how organizations may use automated communications, including SMS text messages, to reach individuals on their mobile phones. Originally passed in 1991, the TCPA has been updated repeatedly through FCC rulemaking, and courts continue to interpret its reach. In 2026, it remains the primary federal framework regulating commercial and informational text messaging in the United States.
The law applies broadly. Whether you are a nonprofit sending fundraising appeals, a hospital system sending appointment reminders, a school district communicating with families, or a government agency notifying constituents, the TCPA likely applies to your outbound SMS program. Assuming your organization is exempt because it is mission-driven or nonprofit is one of the most common, and costly, mistakes organizations make.
Violations can result in significant civil liability, and unlike many regulatory frameworks, the TCPA creates a private right of action, meaning individuals can sue your organization directly, not just file a complaint with a regulator.
What are the TCPA rules for texting in 2026?
If you strip away the case law and the acronyms, the TCPA rules for texting reduce to a short list of operating requirements. Every one of them applies whether you send ten messages a week or ten thousand a day.
- Consent before contact. Automated marketing and promotional texts require prior express written consent. Purely informational or transactional texts still require prior express consent, which the recipient typically gives by knowingly providing their number for that purpose.
- Identify yourself. Every message should make clear which organization is sending it. Anonymous or misleading sender identification undermines consent and invites complaints.
- Respect quiet hours. Telemarketing rules restrict outreach to between 8 a.m. and 9 p.m. in the recipient's local time zone. Schedule campaigns against the recipient's time zone, not your office's.
- Honor opt-outs immediately. STOP and similar keywords must suppress the number across your program, and FCC rules that took effect in 2025 require senders to honor revocation made through any reasonable means, processed within ten business days at most.
- Keep proof. The sender carries the burden of demonstrating consent. No record means no defense.
State legislatures have also passed their own mini-TCPA statutes, several of which impose stricter consent and quiet-hour standards than federal law. A compliant program in 2026 accounts for both layers.
Express written consent: the foundation of a compliant program
Before sending any marketing or promotional text message using an automated system, your organization must obtain express written consent from the recipient. This is a higher standard than a simple opt-in, it requires the individual to affirmatively agree to receive messages from your organization, with a clear disclosure of what they are consenting to.
A compliant opt-in should include:
- The organization's name
- A clear description of the message type (e.g., fundraising updates, appointment reminders, program alerts)
- Estimated message frequency or a statement that it may vary
- A disclosure that message and data rates may apply
- Instructions for opting out (e.g., "Reply STOP to unsubscribe")
- A link to your privacy policy and terms of service
Consent obtained for one purpose does not transfer to another. If a donor opts in to receive donation receipts, that consent does not cover sending them fundraising campaigns. Keep consent buckets distinct, and document each one clearly.
For healthcare organizations, it is worth noting that TCPA consent and HIPAA authorization are separate requirements. A patient may have signed a HIPAA-compliant authorization, but that does not satisfy the TCPA's express written consent requirement for automated messaging. Both frameworks apply. See our guide on HIPAA-compliant text messaging for detail on how the two obligations interact.
Opt-out handling: honoring STOP is not optional
When a recipient replies STOP, QUIT, CANCEL, END, or UNSUBSCRIBE to any of your messages, you are required to honor that request immediately. Sending any further marketing or promotional messages to that number, other than a single confirmation of the opt-out, constitutes a TCPA violation.
Your opt-out process should:
- Remove the number from all active sending lists within seconds of the STOP reply
- Send a single, brief confirmation message (e.g., "You have been unsubscribed and will receive no further messages from [Org Name].")
- Suppress the number across all campaigns, not just the one from which they unsubscribed
- Log the opt-out with a timestamp for your records
Note that under current FCC rules, recipients are not limited to official keywords. A reply like "please stop texting me" or a verbal request through your support line counts as revocation through a reasonable means, and your process needs to capture and honor it just as reliably as a STOP reply.
One area organizations often miss: if a contact re-opts in after previously opting out, you must collect fresh, documented consent before resuming sends. Reactivating a suppressed number without a new consent record puts you back at risk.
Record-keeping: if you cannot prove consent, you do not have it
In a TCPA dispute, the burden falls on the sender to demonstrate that valid consent existed. That means documentation is not a back-office formality, it is your primary legal defense. Every consent record should capture:
- The phone number that consented
- The date, time, and method of consent (web form, text keyword, paper form, etc.)
- The exact language of the opt-in disclosure the individual agreed to
- The IP address or device identifier where applicable
- Any subsequent opt-out or re-opt-in events with timestamps
Store these records in a system that is durable, searchable, and backed up. Spreadsheets are not a sufficient long-term solution. FRANSiS™ captures and stores consent and opt-out events automatically, with data protected by encryption in transit (TLS 1.3) and at rest (256-bit AES), so your records remain intact and retrievable when you need them. Our complete guide to SMS for nonprofits covers how to structure your consent workflow from the ground up.
TCPA compliance checklist for text messaging
Use this checklist to audit your current SMS program or stand up a new one. If you cannot check every box, treat the gaps as your priority list.
- Consent capture: every opt-in flow (web form, keyword, paper, event kiosk) displays your organization name, message type, frequency note, "message and data rates may apply" disclosure, STOP instructions, and privacy policy link.
- No pre-checked boxes: the SMS opt-in is unchecked by default and separate from other form consents.
- Purpose separation: consent is tracked per message category, and lists are never cross-used without fresh consent.
- Opt-out automation: STOP, QUIT, CANCEL, END, UNSUBSCRIBE, and free-text revocation requests suppress the number across every campaign automatically.
- Revocation window: all revocation requests, in any channel, are processed within ten business days, and ideally within seconds.
- Quiet hours: sends are scheduled between 8 a.m. and 9 p.m. in each recipient's local time zone.
- Record retention: consent and opt-out events are logged with timestamps, source, and the exact disclosure language, in a durable searchable system.
- List hygiene: no purchased or rented lists, and reassigned-number checks run before campaigns.
- Carrier registration: your brand and use cases are registered under 10DLC, and registered use cases match your actual sends.
- Staff training: everyone who can hit send understands consent categories, quiet hours, and the opt-out process.
- Annual review: a yearly audit of opt-in language, suppression logic, and state-law changes, with legal counsel where possible.
SMS compliance checklist: beyond the TCPA
TCPA compliance is necessary but not sufficient. A complete SMS compliance checklist also covers the adjacent frameworks that apply to most mission-driven senders:
- 10DLC registration: a carrier-level requirement for application-to-person messaging, separate from the TCPA but enforced through filtering and suspensions.
- CTIA messaging guidelines: industry best practices carriers expect senders to follow, including content restrictions and opt-in standards.
- HIPAA: if messages contain protected health information, HIPAA compliance supported with a signed BAA is required alongside TCPA consent.
- FERPA: education institutions texting about student records need FERPA-aware handling of that information.
- State mini-TCPA laws: states such as Florida, Oklahoma, and Washington have enacted their own telemarketing statutes with independent penalties and, in some cases, tighter quiet hours.
TCPA considerations specific to nonprofits
Nonprofits often operate under the assumption that their mission-driven status affords them regulatory flexibility. It does not, at least not under the TCPA. The law distinguishes between commercial and non-commercial messages in some contexts, but courts have broadly interpreted automated text messaging to fall within the TCPA's scope regardless of the sender's tax status.
Specific areas where nonprofits frequently encounter risk:
- Fundraising appeals sent by text, treated as marketing messages requiring express written consent
- Event invitations and volunteer recruitment, if sent via automated system, consent requirements apply
- Peer-to-peer SMS at scale, if the platform uses any degree of automation, the TCPA applies
- Purchased or rented contact lists, consent obtained by a third party for a different purpose does not transfer to your organization
The safest approach is to build consent collection into every touchpoint where a supporter interacts with your organization, donation forms, event registrations, volunteer sign-ups, and to make the SMS opt-in explicit and separate from other form fields. For a look at how compliant two-way texting works in practice for mission-driven teams, see our nonprofit texting solutions page.
TCPA considerations specific to healthcare organizations
Healthcare senders face the most layered compliance picture of any vertical, because TCPA consent rules interact with HIPAA and with carrier requirements at the same time.
Appointment reminders and informational health messages
Texts that are informational rather than promotional, such as appointment reminders, prescription notifications, and care follow-ups, generally require prior express consent rather than the stricter written standard. In most cases a patient who knowingly provides their mobile number to a provider for those communications has given that consent. The safe practice is still to disclose the texting program at intake, record the consent, and give patients an easy way to decline.
Marketing and wellness promotion require the written standard
The moment a message promotes a service, program, or paid offering, it crosses into marketing territory and requires prior express written consent, even when the sender is a healthcare provider and the content is health-related. Flu-shot promotion campaigns, new-service announcements, and wellness program upsells all belong in this bucket. Keep these lists separate from your reminder lists, with separate consent records for each.
Healthcare organizations also need to keep protected health information out of message content unless HIPAA safeguards are in place, which is a content question the TCPA does not address at all. A platform built for regulated senders should handle both: FRANSiS supports TCPA-aware consent management alongside HIPAA compliance supported with a signed BAA. Learn more on our healthcare texting solutions page.
How 10DLC fits into your TCPA compliance strategy
10DLC, 10-digit long code, is the carrier-level infrastructure now required for most application-to-person (A2P) SMS messaging in the United States. While 10DLC registration is a carrier requirement rather than a TCPA requirement, the two are deeply connected in practice.
Carriers require organizations to register their brand and describe the use cases for which they will send messages. The use-case descriptions you submit during 10DLC registration must accurately reflect the consent you obtained. Sending messages for a purpose not covered in your registered use case, even if the recipient consented to something else, can result in filtering, suspension, or carrier penalties that compound your TCPA exposure.
For a detailed walkthrough of the registration process, see our 10DLC registration guide. FRANSiS supports 10DLC registration and helps organizations align their carrier registration with their consent framework so both requirements are satisfied together.
How to choose a TCPA-compliant texting platform
No platform makes an organization compliant on its own, because compliance ultimately depends on how you collect consent and manage your lists. What the right platform can do is make the compliant path the default path. When evaluating vendors, look for:
- Automatic consent logging that records the timestamp, source, and disclosure language for every opt-in without manual data entry
- Universal opt-out suppression that honors STOP keywords and free-text revocation across all campaigns instantly
- Quiet-hours enforcement based on each recipient's local time zone, not the sender's
- Audit-ready exports so you can produce consent evidence quickly if a dispute arises
- 10DLC registration support, including help aligning registered use cases with your consent categories
- A signed BAA if you handle protected health information, plus encryption in transit (TLS 1.3) and at rest (256-bit AES)
- Two-way conversation handling, because recipients reply with questions, and an AI Powered Helper that routes and answers those replies keeps opt-out and consent signals from slipping through the cracks
- Predictable cost, so compliance-driven message volume (confirmations, disclosures, reminders) does not create budget pressure to cut corners; FRANSiS pricing is flat, predictable, unlimited messaging
Ask every vendor to walk you through exactly what happens, step by step, when a contact replies STOP and when a contact replies "stop texting me please." The quality of the answer tells you most of what you need to know.
Frequently asked questions
Does the TCPA apply to nonprofit organizations?
Yes. Nonprofit status does not exempt an organization from the TCPA. If your organization sends text messages using automated systems, including most SMS platforms, you are required to obtain express written consent and honor opt-out requests, just as any commercial sender would be.
What counts as express written consent under the TCPA?
Express written consent is an affirmative agreement by the recipient to receive automated text messages from your organization. It must include a clear disclosure of the message type, the sender's name, opt-out instructions, and a note that message and data rates may apply. A pre-checked checkbox or implied consent from a prior relationship does not meet this standard.
How quickly must organizations honor a STOP request?
Opt-out requests must be honored immediately. After a recipient replies STOP, you may send a single confirmation message and must then cease all further automated outreach to that number. Organizations that continue sending messages after a STOP reply are exposed to TCPA liability on each subsequent message sent.
Is TCPA consent the same as HIPAA authorization for healthcare text messaging?
No. TCPA consent and HIPAA authorization are separate legal requirements that operate independently. A patient's HIPAA authorization does not satisfy the TCPA's express written consent requirement for automated SMS, and vice versa. Healthcare organizations must meet both standards. Using a platform that supports both HIPAA-compliance workflows (with a BAA) and TCPA-compliant consent management helps address both obligations from a single system.
What is the penalty for violating the TCPA?
The TCPA imposes statutory damages that are assessed per violating message, with increased amounts available for willful or knowing violations. Because damages accrue message by message, a single non-compliant campaign sent to a large list can create substantial exposure, and the private right of action means class actions are common. The practical takeaway: treat every send as if you will one day need to prove consent for it.
Are there quiet hours for sending text messages?
Yes. Federal telemarketing rules restrict outreach to between 8 a.m. and 9 p.m. in the recipient's local time zone, and several state laws impose narrower windows. Configure your platform to schedule against each recipient's time zone rather than your own, and hold non-urgent informational messages to the same window as a best practice.
Can someone revoke consent without replying STOP?
Yes. Under FCC rules that took effect in 2025, consumers may revoke consent through any reasonable means, including free-text replies, emails, or phone calls, and senders must process the revocation within ten business days. Your suppression workflow should capture these signals automatically rather than relying on staff to spot them in an inbox.
Do appointment reminder texts require written consent?
Generally no. Purely informational messages such as appointment reminders require prior express consent, which a patient or client typically provides by knowingly giving their number for that purpose. The stricter express written consent standard applies once messages become promotional. Because the line between informational and marketing content can blur, many organizations apply the written standard across the board to stay safely inside it.
Related guides: TCPA Class Action Lawsuits: Lessons for Mission Driven Orgs · TCPA Violations and Penalties: What Fines Actually Look Like
Sign up for our mailing list for insights, perks, and more!


