What constitutes a TCPA violation?
Learn what constitutes a TCPA violation, from autodialed calls to consent gaps, plus how to avoid $500–$1,500 penalties per call and vet vendor compliance.

What constitutes a TCPA violation?
Key Facts
- Each TCPA violation carries statutory damages of $500 to $1,500, and claims can surface up to four years later, according to legal analysis of the statute.
- The largest TCPA fine ever imposed was $299,997,000, levied by the FCC against ten companies behind 5+ billion illegal robocalls, industry reports show.
- Dish Network paid a $210 million settlement covering 66+ million telemarketing violations — including calls made by its own dealers, per case analysis.
- Capital One paid $75.5 million for autodialed calls to cell phones without consent, the largest TCPA settlement to date.
- The Seventh Circuit ruled that texts are not "telephone calls" under DNC provisions, though automated SMS can still violate other TCPA sections, according to the ruling.
- The FCC's one-to-one consent rule was vacated, so one written consent can now authorize calls from multiple named sellers if clearly disclosed, per TCPA damages guidance.
- The *Facebook v. Duguid* ruling narrowed the autodialer definition to equipment using a random or sequential number generator, legal experts note.
Why TCPA Violations Catch Growing Businesses Off Guard
Most businesses that get hit with a TCPA lawsuit never set out to break the law. They simply started reaching out to more leads — and the law was waiting.
The stakes are real. TCPA violations carry statutory damages of $500 to $1,500 per violation, and claims can be brought up to four years after the fact, according to legal analysis of the statute. That means a mistake made today can surface as a lawsuit long after the campaign ended.
The settlement history shows how fast penalties compound. Capital One paid $75.5 million for autodialed calls to cell phones without consent. Dish Network settled for $210 million after more than 66 million telemarketing violations — including calls made by its own dealers. That last detail matters: you can be liable for what your vendors do.
High-volume outreach creates outsized exposure because of simple multiplication. If each unwanted call or text counts as a violation, a campaign touching thousands of contacts can generate damages in the millions. High-volume enterprise callers routinely face class action damages exceeding hundreds of millions of dollars. The more leads you work, the bigger the target on your back.
Vague definitions make accidental violations common. What counts as an autodialer, what counts as valid consent, and what happens when a number gets reassigned are all murky areas. Attorney Eric J. Troutman notes the TCPA has become a litigation cash cow, with litigators actively hunting for technical missteps. Common tripwires include:
- Calling cell phones for marketing without prior express written consent
- Using automated or prerecorded technology without clear consent
- Contacting numbers on the National Do Not Call Registry
- Missing a consumer's revocation request buried in a reply text
- Inheriting violations from a lead vendor or dealer acting on your behalf
The rules also shift. The FCC's one-to-one consent rule was vacated, reinstating the pre-2023 written consent standard. The Seventh Circuit recently held that texts are not "telephone calls" under the DNC provisions — though automated SMS campaigns may still violate other sections of the statute. A practice that was risky last year may be safer now, and vice versa.
This is why fast follow-up and compliance have to travel together. At Worqd, we build outreach around explicit, permission-aware consent from the first click — because growing your pipeline shouldn't mean growing your legal risk. When you're evaluating any growth partner, ask how they handle consent records, do-not-call requests, and vendor liability before you ask about conversion rates.
The Five Actions That Trigger a TCPA Violation
The Telephone Consumer Protection Act (TCPA) is a complex regulatory landscape that imposes strict consent requirements and penalties for violations. According to industry reports, key actions that constitute TCPA violations include making calls without prior express written consent, using autodialers or prerecorded voices without consent, and calling numbers listed on the National Do Not Call Registry.
Companies face significant compliance challenges due to ambiguous definitions and practical issues such as reassigned numbers, vendor compliance, and consumer revocation requests. As legal experts note, the TCPA's revocation rules empower consumers to demand that calls stop, which can be difficult to track and implement.
To avoid TCPA violations, companies should focus on the following key areas:
- Obtaining prior express written consent for marketing calls to cell phones
- Implementing robust compliance practices, including maintaining a company-specific do-not-call list
- Monitoring and updating consent records to ensure compliance with TCPA regulations
As recent studies have shown, the autodialer definition has been narrowed following the Facebook v. Duguid ruling, which requires equipment to store or produce numbers using a random or sequential number generator to qualify as an automatic telephone dialing system.
The statutory damages for TCPA violations can be substantial, ranging from $500 to $1,500 per violation. In fact, the largest TCPA penalty was $299,997,000, imposed by the FCC against ten companies for 5+ billion illegal robocalls, as reported by industry sources. To mitigate these risks, companies like Worqd prioritize compliance and provide comprehensive training to employees and vendors on TCPA regulations.
By understanding the specific triggers for TCPA violations and implementing comprehensive compliance strategies, businesses can minimize their risk of non-compliance and avoid costly penalties. As recent court rulings have highlighted, the TCPA landscape is constantly evolving, and companies must stay up-to-date on the latest developments to ensure compliance. With the right approach, businesses can navigate the complex world of TCPA compliance and focus on driving growth and revenue.
What the Latest Rulings Change (and What Still Applies)
The TCPA landscape has seen significant shifts in recent rulings, leaving marketers to navigate a more complex compliance environment. Understanding what remains applicable and what has changed is crucial for ensuring your lead generation and follow-up strategies stay within legal bounds.
The Seventh Circuit's ruling that text messages do not qualify as "telephone calls" under the TCPA's Do-Not-Call (DNC) provisions eliminates the private right of action for unwanted SMS under § 227(c)(5). However, this does not mean automated SMS campaigns are entirely exempt from TCPA regulations. These campaigns can still violate § 227(b), which governs the use of automatic telephone dialing systems (ATDS) and prerecorded voices. According to legal experts, companies must ensure that their automated SMS campaigns comply with the consent requirements outlined in § 227(b).
One critical aspect of TCPA compliance is obtaining prior express written consent for marketing calls to cell phones. This requirement has seen recent adjustments. The FCC's one-to-one consent rule has been vacated, reinstating the pre-2023 prior express written consent standard. This means that a single written consent can authorize calls from multiple named sellers, provided the consent clearly discloses all potential callers. For example, a single written consent can now permit calls from various entities if the consumer is informed about each entity upfront.
When choosing a provider for lead generation and follow-up services, it's essential to assess their compliance practices thoroughly. Companies like Worqd prioritize personalized, permission-aware outreach to relevant accounts, ensuring compliance with TCPA regulations. This approach helps in generating more demand and faster follow-up, which are crucial for converting leads into booked calls. Additionally, Worqd’s services include AI SDRs that respond instantly to inquiries, qualifying leads in under 60 seconds, 24/7.
Compliance challenges persist, with companies facing issues such as reassigned numbers and consumer revocation requests. According to industry research, the TCPA's revocation rules empower consumers to demand that calls stop, which can be difficult to track and implement. To mitigate these risks, companies should:
- Implement robust compliance practices, including maintaining a company-specific do-not-call list and honoring all DNC requests.
- Monitor and update consent records regularly to ensure compliance with TCPA requirements.
- Provide comprehensive training to employees and vendors on TCPA compliance, covering proper handling of consent and the use of autodialers.
- Conduct regular audits of telemarketing practices to identify and address potential TCPA violations.
By staying informed about the latest TCPA rulings and implementing comprehensive compliance strategies, companies can avoid significant penalties and legal exposure. Understanding these changes and adapting your practices accordingly will help ensure that your lead generation and follow-up efforts remain effective and compliant. To learn more about how Worqd can help you stay compliant while generating more leads and converting them into booked calls, book a growth call with our team today. Our insights hub also offers valuable resources on TCPA compliance and best practices.
How to Build a TCPA-Compliant Outreach Process
The TCPA turns small outreach mistakes into five- and six-figure liabilities — and in some cases, much larger. TCPA damages guidance notes that each violation carries statutory damages of $500 to $1,500, and the FCC has imposed fines as large as $299,997,000 against ten companies behind billions of illegal robocalls, according to industry analysis of the largest TCPA cases.
The foundation of any compliant outreach process is prior express written consent before marketing calls to cell phones. Legal experts note that this requirement applies specifically to marketing calls, while non-marketing calls may only need prior express consent, as explained in this TCPA compliance overview.
The consent landscape shifts, so staying current matters. The FCC's one-to-one consent rule was vacated, reinstating the pre-2023 standard that allows a single written consent to authorize calls from multiple named sellers if clearly disclosed, according to TCPA damages and lawsuit guidance.
Consent alone is not enough — you must prove it. Keep detailed records of every authorization, including the date, method, and content of the consent. If a consumer later disputes what they agreed to, your records are the only evidence you have. A solid consent record should capture:
- The exact date and time consent was given
- The method used to obtain it (form, checkbox, or verbal confirmation)
- The specific language the consumer agreed to
- The phone number and campaign covered by the consent
- Any revocation requests and when they were honored
Next, maintain a company-specific do-not-call list and honor all requests for at least five years, as outlined in the TCPA's statutory framework. Check this list before every outreach attempt, not just at campaign launch.
Training is just as critical. The Dish Network case shows why: the company paid a $210 million settlement for 66+ million telemarketing violations, including calls made by its own dealers. Every employee and vendor who touches outreach needs to understand consent rules, DNC obligations, and how to handle revocation requests.
Finally, run regular compliance audits. Review call logs, consent records, and DNC lists to catch problems before they become class actions, as recommended in this legal analysis of TCPA enforcement. An audit might feel like overhead — until it catches a revocation that slipped through the cracks or a vendor that ignored a do-not-call request.
This is where compliance and conversion meet. Worqd builds explicit opt-in consent directly into its booking funnel, and its B2B outreach is permission-aware, personalized outreach — the opposite of a template blast. When consent is built into the process from the first touch, the outreach that follows is both legally defensible and more effective.
How to Vet a Growth Partner's Compliance Practices
When you hire a growth partner to run calls, texts, or outreach on your behalf, their compliance failures become your liability. A vendor's TCPA violation is your TCPA violation — and the financial exposure is substantial.
The numbers make the risk concrete. Under the TCPA, violations carry statutory damages ranging from $500 to $1,500 per violation, and the largest settlement to date reached $75.5 million, paid by Capital One. Dish Network paid $210 million for 66+ million telemarketing violations — including calls made by its own dealers. That last detail is the one that should keep you up at night: the brand was held accountable for what its partners did. And with a four-year statute of limitations, a compliance gap can surface long after a campaign ends.
So before you sign with anyone who runs calls, texts, or outreach for you, ask these questions:
- Who owns the consent records? Prior express written consent is required for marketing calls to cell phones. If your vendor captures consent on your behalf, you need access to the full record — the date, method, and exact language of every opt-in. The vacated one-to-one consent rule means a single written consent can authorize calls from multiple named sellers, but only if the disclosure is explicit.
- How are do-not-call requests handled? The TCPA requires a company-specific DNC list that is honored for at least five years. Ask who maintains that list and how quickly a suppression request propagates across every active campaign. If they run SMS, note that the Seventh Circuit recently ruled texts are not "telephone calls" under the DNC provisions — but automated messages can still trigger liability under other TCPA sections.
- How are vendors held accountable? Dish Network's case proves a brand can pay for its dealers' violations. Your contract needs explicit compliance obligations, audit rights, and real consequences for failures.
- What happens when a lead asks to stop? Revocation requests must be tracked and implemented. Ask to see the actual workflow — not a policy document, the system that runs it.
The fragmented approach — one vendor for ads, another for creative, a third for follow-up — makes these questions nearly impossible to answer. Consent records live in one place, call logs in another, and no single party owns the full picture. When something goes wrong, accountability evaporates.
That is why Worqd runs the entire path from first click to booked call under one accountable process. Outreach is personalized and permission-aware rather than a template blast, consent is captured explicitly at the point of request, and every inquiry is qualified in under 60 seconds. One partner means one set of records, one DNC process, and one party responsible for compliance — not a chain of vendors pointing at each other.
Frequently Asked Questions
What are the most common TCPA violations businesses face?
What are the potential penalties for a TCPA violation?
Do I need consent for all types of calls, and what does it look like?
Can I be held liable for my vendor's TCPA violations?
How has the recent ruling on text messages affected TCPA compliance?
What steps can I take to ensure my outreach is TCPA compliant?
Growth Shouldn't Come With a Lawsuit Attached
The TCPA punishes the same mistake a thousand different ways: $500 to $1,500 per violation, a four-year window to sue, and liability for what your vendors do — as Dish Network's $210 million settlement for 66+ million violations, many made by its own dealers, made painfully clear. The rules also keep moving, from the vacated one-to-one consent rule to the Seventh Circuit's ruling on text messages, so a campaign that was safe last year may not be safe now. The fix is simple in principle: get prior express written consent, keep records that prove it, honor every do-not-call and revocation request, and audit your outreach before a litigator does. If you're handing outreach to a partner, ask who owns the consent records and how fast a suppression request propagates — their gaps become your liability. Worqd builds explicit, permission-aware consent into every campaign from the first click, so faster follow-up doesn't mean bigger risk. Want to see what compliant, high-converting outreach looks like? Book a growth call with our team.
Want help putting this into action?
Book a Growth Call