TCPA COMPLIANCE CALL-CENTER

TCPA Compliance Checklist for 2026

SIPNEX ·

If you run a predictive dialer, you need a TCPA compliance checklist — because you live under the TCPA whether you think about it or not. The Telephone Consumer Protection Act is the largest source of legal risk for outbound calling in the United States. Penalties run $500 per violation for negligent conduct, and $1,500 when it is willful. A single campaign touching 50,000 numbers can rack up 50,000 separate violations. Class action firms specialize in these cases because the math is simple and the settlements are large.

This TCPA compliance checklist comes from SIPNEX, an FCC-licensed carrier. We provide SIP trunks for predictive dialers and VICIdial operations. We are not lawyers, and this is not legal advice. We are the carrier that sees compliance from the infrastructure side. We watch the call traffic, handle the STIR/SHAKEN attestation, and field questions from operators trying to stay legal while dialing at scale.

What is a TCPA compliance checklist?

A TCPA compliance checklist is a documented set of controls that keeps outbound calling within the Telephone Consumer Protection Act. The core controls: consent capture, DNC scrubbing every 31 days, 8 a.m.–9 p.m. recipient-local calling hours, sub-3-percent abandon rates, and litigation-ready records that prove each control.

The condensed TCPA compliance checklist for business dialer operations:

  1. Capture prior express written consent before autodialed telemarketing calls to cell phones.
  2. Store consent proof — disclosure language, timestamp, method, phone number.
  3. Honor revocation immediately, made by any reasonable means.
  4. Scrub the National DNC Registry every 31 days.
  5. Maintain a company-specific DNC list; honor requests for 5 years.
  6. Scrub state DNC registries (Indiana, Pennsylvania, Colorado, others).
  7. Dial only 8 a.m.–9 p.m. in the recipient’s local time zone.
  8. Keep predictive-dialer abandon rate below 3 percent.
  9. Include caller identity, purpose, and opt-out in prerecorded messages.
  10. Document policy, train staff, audit CDRs quarterly.

The full audited checklist, with the proof each control needs, is in the sectioned checklist below.

What TCPA is and why enforcement accelerated

The Telephone Consumer Protection Act (47 U.S.C. § 227) became law in 1991 to shield consumers from unwanted sales calls. It has changed several times since, most notably through FCC orders in 2012, 2015, 2021, and 2024-2025. The statute covers autodialed calls, prerecorded or artificial voice messages, unsolicited fax ads, and text messages.

The core rule: you cannot call or text a cell phone with an automatic telephone dialing system (ATDS) or a prerecorded voice without the called party’s prior express consent. For telemarketing calls, the bar is higher — you need prior express written consent. The texting rules, including the 2025 revocation order, get their own treatment in TCPA text message compliance.

Damages are statutory. The plaintiff does not need to prove real harm. Each call or text is a separate violation. The baseline is $500 per violation. Courts can triple that to $1,500 for willful or knowing conduct. A campaign that dials 10,000 cell phones without valid consent faces $5 million to $15 million in exposure — before legal fees.

Enforcement has sped up for three reasons. First, the FCC issued new orders in 2024 and 2025. They tightened consent rules, narrowed the established business relationship, and widened what counts as an ATDS in some contexts. Second, the plaintiffs’ bar got smarter. Class action firms use analytics to spot high-volume callers and build cases before one consumer complains. Third, state attorneys general now bring their own TCPA-style actions under state telemarketing laws. That opens a second front of risk.

The practical point for operators: TCPA compliance is not a box you check once during campaign setup. It is an ongoing discipline. It touches your consent capture, your data handling, your dialer setup, your DNC process, and your carrier relationship.

TCPA consent comes in two tiers, and mixing them up is one of the most common failures. Getting consent at the right tier — and proving it later — decides most TCPA cases before they start.

Prior express consent is the baseline. It means the person gave you their number by choice, in a setting where they would expect calls. Example: a customer fills out a form on your website and lists a cell number as their contact. By sharing the number, they consent to informational calls tied to that transaction or relationship. Think appointment reminders, account updates, or service notices. This consent does NOT cover telemarketing.

Prior express written consent is the higher tier. It applies to telemarketing calls made with an autodialer or prerecorded voice to cell phones. It requires a written agreement, on paper or electronic. The agreement must clearly state that the person will get autodialed or prerecorded telemarketing calls. It must name the exact phone number to be called. And it must carry the person’s signature or e-sign equivalent.

The agreement cannot hide inside a terms of service. It must be a standalone disclosure the person actively accepts. And it cannot be a condition of purchase — you cannot demand consent before someone can buy from you.

A sample disclosure — have your counsel review before use:

By checking this box, I agree to receive marketing calls and texts from [Company] at the number provided, including via autodialer and prerecorded voice. Consent is not a condition of purchase. Message and data rates may apply. Reply STOP to opt out.

The tiers at a glance:

Call typeConsent requiredApplies to
Informational or transactional call or textPrior express consentCell phones (autodialed or prerecorded)
Telemarketing via autodialer or prerecorded voicePrior express written consentCell phones
Live, manually dialed telemarketing callDNC rules apply — no written-consent tierLandlines and cell phones
Prerecorded telemarketing messagePrior express written consentResidential landlines

Consent capture and storage is where operators lose lawsuits. You may hold valid consent. But if you cannot prove it two years later when the lawsuit arrives, it does not matter. Store the exact disclosure text the person agreed to, the timestamp, the method (web form, verbal recording, paper), the phone number, and any transaction ID. For web forms, keep the page URL, form version, IP address, and browser details. For verbal consent, record the call and store the recording with metadata that links it to the consent event.

Revocation is a right the person can use at any time, by any reasonable means. The FCC’s 2025 rules made this explicit. Someone can revoke by telling your agent on the phone, texting “stop,” sending an email, or any other clear method. You must honor it at once. The FCC has signaled that “at once” means within a reasonable technical window — not at the end of the campaign or billing cycle.

Build revocation into your dialer workflow. When an agent hears a verbal opt-out, the number must land on your internal DNC list during the call — not after it.

The ATDS question after Facebook v. Duguid

The meaning of “automatic telephone dialing system” has been the most litigated question in TCPA law for a decade. The statute defines an ATDS as equipment that can store or produce phone numbers using a random or sequential number generator, and then dial them.

In April 2021, the Supreme Court decided Facebook v. Duguid and narrowed that definition. A device must actually use a random or sequential number generator to qualify. Merely storing and dialing numbers from a list is not enough. This was a big win for businesses. It excluded most modern dialers, which work from uploaded lead lists rather than random numbers.

The story did not end there. The FCC has since read the ATDS definition more broadly in some contexts. Circuit courts disagree with each other. Some state laws, like Florida’s Telephone Solicitation Act, use wider ATDS definitions that Duguid never touched. And the plaintiffs’ bar changed tactics. Instead of arguing ATDS, many suits now target consent defects, revocation failures, or DNC violations — issues Duguid did not affect.

For VICIdial and predictive dialer operators: VICIdial dials from uploaded lead lists, not random numbers. Under Duguid, that likely means VICIdial is not an ATDS for federal purposes. But “likely” is not “certainly,” and state laws may differ. The safe path is to treat your dialer as an ATDS and get prior express written consent for telemarketing calls. With written consent on file, the label no longer matters — you already met the higher standard.

Bottom line: treat every dialer as an ATDS and get written consent — then the classification fight never touches you.

DNC compliance: federal and state

The Do Not Call rules sit apart from the ATDS and consent framework. They trip up operators who focus only on consent.

The National Do Not Call Registry is run by the FTC. Before placing telemarketing calls, scrub your lists against it. Do it at least every 31 days — the registry updates monthly, and numbers can be added at any time. Dialing a list that has gone unscrubbed for more than 31 days puts you at risk. Access it at telemarketing.donotcall.gov. There is a per-area-code fee, and it is trivial next to the cost of one violation.

Company-specific DNC lists are separate from the National Registry. When a person tells you to stop calling — by any means — add them to your internal DNC list. Honor that request for at least five years. This applies even if they never joined the National Registry. The list is yours to keep; the FCC offers no central system for it. Build it into your CRM. When an agent marks a call “do not call,” that number must drop out of every future campaign, not just the current one.

State DNC lists add another layer, and many operators miss it. Indiana, Pennsylvania, Colorado, and several other states keep their own do-not-call registries. If you call into those states, scrub against the state registry too. Penalties vary, but some states allow private lawsuits much like the federal TCPA.

EBR (Established Business Relationship) exceptions exist, but they are narrower than most operators think. An existing customer relationship exempts you from the National Registry for 18 months after the last transaction, or 3 months after the last inquiry. The exception does NOT override a company DNC request. If the customer says “do not call me,” the EBR is gone, no matter how fresh the relationship. And some states do not recognize the exception at all.

Vendors, lead sellers, and calls made on your behalf

The TCPA does not stop at your own dialer. Courts apply vicarious liability: you can be on the hook for calls that agencies, lead vendors, and outside call centers place for you. “The vendor did it” is not a defense when the campaign runs in your name and for your benefit.

Three controls close most of the gap. First, demand consent proof from every lead seller — the disclosure text the person saw, the timestamp, and the source URL. If a vendor cannot produce that for each record, treat the list as unconsented. Second, audit vendor contracts for TCPA warranty and indemnification language. Make compliance a term of the deal, not a handshake.

Third, test purchased lists before a campaign, not after. Run them against your own company DNC list and the National Registry, and spot-check consent records for a sample of numbers. A vendor’s “pre-scrubbed” label is marketing, not evidence — our DNC scrubbing guide covers why the scrub that matters legally is your own.

Calling hours and restrictions

The federal TCPA limits telemarketing calls to 8:00 a.m.–9:00 p.m., local time of the called party. This is one of the most violated rules. The time zone that matters is not yours — it is the recipient’s.

Say your call center is in Texas (Central Time) and you start dialing at 8:00 a.m. Central. You are calling at 9:00 a.m. Eastern — fine. But you are also calling at 6:00 a.m. Pacific. That is a violation for every call landing in California, Oregon, Washington, Nevada, or any other Pacific Time state. By 9:00 p.m. Central, it is 10:00 p.m. Eastern — and every East Coast call in that last hour was a violation.

The fix is not hard, but it needs deliberate setup. Work out the time zone of each lead, starting from the area code. Then apply NPA-NXX (area code plus prefix) data for better accuracy. Some area codes span two time zones — 219 in Indiana covers both Eastern and Central. When in doubt, use the stricter zone.

In VICIdial, set your hopper filters to enforce calling windows by time zone. Set campaign hours to the most restrictive window. For continental US campaigns, that means 11:00 a.m.–9:00 p.m. Eastern, which is 8:00 a.m.–6:00 p.m. Pacific. Then adjust per list or per filter based on where your leads live.

State rules vary. Some states trim the window further — Oregon ends telemarketing calls at 8:00 p.m. (ORS 646.563), an hour before the federal cutoff. Some bar calls on certain holidays or Sundays. If you dial nationally, build a state-level calling-hours matrix and wire it into your hopper setup.

What changed in 2025 and 2026

Two changes matter most for this year’s checklist. Both are already baked into the items below.

Revocation got teeth. The FCC’s 2024 revocation order took effect on April 11, 2025. People may now revoke consent by any reasonable means — no special keyword, no single channel. Callers must honor the request within a reasonable time, and never more than 10 business days. Our checklist holds you to one business day. That is stricter than the legal outer bound on purpose: every call after a revocation is a fresh violation.

One-to-one consent died in court. The FCC’s one-to-one consent rule for lead generators was vacated by the Eleventh Circuit on January 24, 2025, in Insurance Marketing Coalition v. FCC — just before its effective date. The older written-consent standard governs again. Do not relax, though. Lead buyers still carry the burden of proving valid consent for every purchased record. The full story is in our answer to what happened to the one-to-one consent rule.

The carrier’s role vs your role

Most operators skip this section. It is also the part that decides whether you picked the right carrier. The full carrier-vs-operator duty matrix lives on our TCPA compliance for operators page — the short version follows.

What SIPNEX provides (carrier-level compliance infrastructure):

STIR/SHAKEN attestation — we sign your calls with our own SP-KI certificate. If your DIDs are verified, you get A-level attestation. This does not make you TCPA-compliant. It does keep your calls from being dragged down by attestation-related spam labeling while you manage your TCPA duties.

Call recording infrastructure — we support carrier-level call recording. Use it for consent proof, quality assurance, and dispute resolution. Recording is a tool. How you use it — including state recording consent laws — is on you.

CDR (Call Detail Record) access — real-time call records with timestamps, durations, and disposition codes. These records are core evidence when you need to prove compliance in court.

Opt-out signaling — the technical plumbing that processes STOP replies on SMS and honors them within carrier-mandated timeframes.

What is YOUR responsibility (campaign-level compliance):

Consent capture and storage. DNC scrubbing against federal and state registries. Company DNC list upkeep. Calling-hour enforcement by recipient time zone. Campaign content rules — required disclosures and opt-out instructions. Abandon-rate control (the FCC requires under 3 percent for predictive dialers). Records strong enough to prove compliance in court.

We give you the infrastructure. You own the policy. SIPNEX is not your lawyer, your compliance officer, or your insurance policy. We are the carrier that gives you a sound technical base — clean attestation, reliable recording, accurate CDRs — so your compliance work does not sit on a reseller trunk that cannot even tell you its attestation level.

The 2026 TCPA compliance checklist

Use this as the starting point for your own program. Every item should be checkable — if you cannot produce proof for a line item, you have a gap. Each line exists to protect you from statutory damages that multiply per call.

  • Written consent forms capture phone number, disclosure language, signature/e-sign, and timestamp
  • Consent records stored with unique identifiers linked to call records
  • Consent language reviewed by legal counsel within the past 12 months
  • Revocation process documented and tested
  • Revocation honored within one business day maximum

DNC

  • National DNC Registry scrubbed within the past 31 days
  • Company-specific DNC list kept current and suppressed across all campaigns
  • State DNC registries scrubbed for applicable states
  • DNC additions processed within 24 hours of request
  • DNC records retained for minimum 5 years

Calling hours

  • Time zone assigned to every lead record
  • Hopper filters enforce 8am-9pm recipient local time
  • State-specific limits applied where they exist
  • No calls placed outside permitted windows in the past 90 days (audit your CDRs)

Dialer configuration

  • Abandon rate tracked and held below 3 percent
  • Prerecorded messages include required disclosures (caller identity, purpose, opt-out mechanism)
  • Live agent connects within 2 seconds of answer for predictive campaigns
  • Ringless voicemail treated as a call under TCPA (the FCC has said it is)

Documentation

  • All of the above documented in a written TCPA compliance policy
  • Policy reviewed and updated at least annually
  • Staff trained on TCPA duties, with training records kept
  • Compliance audits run quarterly using CDR data and DNC records

The SMS side of the checklist

Texts carry the same per-message exposure as calls, plus carrier rules of their own:

  • Written consent captured before any marketing text goes out
  • STOP and the FCC’s standardized revocation keywords honored automatically
  • One opt-out confirmation message sent, then silence
  • Texting quiet hours enforced — the same 8 a.m.–9 p.m. recipient-local rule
  • Consent records tied to each individual number

The full texting framework, including the 2025 revocation rules, is in TCPA text message compliance.

Frequently asked questions

What is TCPA compliance?

TCPA compliance means running your outbound calls and texts within the Telephone Consumer Protection Act (47 U.S.C. § 227) and its FCC rules. In practice, that means getting consent before you call or text. It means honoring the National and company-specific Do Not Call lists, keeping calls inside permitted hours for the recipient’s time zone, and holding abandon rates under FCC limits. It also means documenting all of it well enough to defend a lawsuit. It is not a one-time setup. It is an ongoing discipline of audits, list scrubbing, and policy updates as the FCC issues new guidance.

What are the penalties for TCPA violations?

Statutory damages are $500 per violation — per call or text — for negligent violations, and up to $1,500 per violation for willful or knowing ones. There is no cap on total damages. A campaign that calls 20,000 numbers without valid consent faces $10 million to $30 million in exposure. TCPA cases can run as class actions, which is why plaintiffs’ lawyers chase them so hard.

The FCC can also impose forfeiture penalties on its own. State attorneys general can sue under state telemarketing laws with their own penalty structures. For most calling operations, the financial risk of non-compliance is existential.

Do I need written consent for all outbound calls?

Not all, but for the calls most dialer operators make, yes. Prior express written consent is required for telemarketing calls made with an autodialer or prerecorded voice to cell phones. If you are selling, promoting a service, or soliciting donations with a predictive dialer, you need written consent.

Informational calls — appointment reminders, account alerts, service notices — need only prior express consent: the person gave you their number in a relevant context. Landline calls with live agents and no recordings follow different rules. The safest practice for any marketing or sales dialer: get written consent for every number you dial.

Is STIR/SHAKEN attestation the same as TCPA compliance?

No. They operate at different layers. STIR/SHAKEN is a carrier-level technical framework that verifies caller ID with cryptography. It decides whether your call shows as “Verified Caller” or gets flagged as likely spam. TCPA is a federal consumer protection law. It governs consent, do-not-call duties, calling hours, and autodialer use.

You can have perfect A-level attestation and still be deep in TCPA violation if you call without consent. You can also have bulletproof consent and still suffer poor answer rates if your carrier only signs at B-level. You need both: the right carrier for attestation, and your own TCPA program for consent and DNC.

Is VICIdial considered an ATDS under TCPA?

After the Supreme Court’s 2021 ruling in Facebook v. Duguid, the federal ATDS definition requires use of a random or sequential number generator. VICIdial dials from uploaded lead lists, not random numbers, so it likely does not qualify as an ATDS under the federal Duguid standard.

But this is not settled law. The FCC and several circuit courts read the definition differently, and some state laws define ATDS more broadly. Florida’s Telephone Solicitation Act, for example, may reach list-based dialers. The safe move: treat VICIdial as an ATDS and get prior express written consent for telemarketing calls. With valid written consent, the label stops mattering.

Am I liable if a lead vendor or agency violates the TCPA on my behalf?

Yes, you can be. Courts apply vicarious liability under the TCPA. When an agency, lead seller, or outside call center dials in your name and for your benefit, the violations can land on you. Plaintiffs usually sue the brand, not the vendor — the brand has deeper pockets, and the campaign ran for its products.

The controls that hold up: demand consent proof (disclosure text, timestamp, source URL) for every purchased record. Put TCPA warranty and indemnification terms in vendor contracts. And run purchased lists through your own DNC suppression before dialing. If a vendor cannot document consent, treat the list as unconsented.

What hours can I legally make telemarketing calls under the TCPA?

Federal law allows telemarketing calls between 8 a.m. and 9 p.m. in the recipient’s local time zone — not yours. A Texas call center dialing at 8 a.m. Central reaches Pacific numbers at 6 a.m., and each of those calls is a violation. State rules can be tighter: Oregon ends calls at 8 p.m., and Kentucky bars them before 10 a.m. Enforce the windows with time-zone-aware hopper filters, and use NPA-NXX data where an area code spans two zones.


SIPNEX is an FCC-licensed carrier with its own STIR/SHAKEN Service Provider certificate. We provide the carrier-level infrastructure — A-level attestation, call recording, real-time CDRs — so your TCPA compliance checklist runs on a solid technical base. Talk to an operator or see our rates.

SIPNEX

The carrier built by operators, for operators.

FCC-licensed carrier with its own STIR/SHAKEN SP certificate. Operator-owned. SIP trunks built for operators who dial at volume.