Back to insights
Checking Compliance Practices

What does TCPA require you to disclose?

Learn what the TCPA requires you to disclose on consent forms, calls, and texts in 2025 — plus how to check a provider's compliance before you hire.

What does TCPA require you to disclose?

What does TCPA require you to disclose?

Key Facts

A single vague disclosure on a lead form can quietly turn a promising campaign into a seven-figure liability. That's not an exaggeration — it's the arithmetic of the Telephone Consumer Protection Act.

The numbers are stark. TCPA violations cost $500 to $1,500 per call or text, with no cap on total penalties, according to compliance guidance. Run a campaign to 5,000 contacts without valid consent and you've created $2.5M–$7.5M in exposure. Even a modest 1,000-contact campaign puts $500K–$1.5M at risk.

And plaintiffs' attorneys know how to scale these claims. Nearly 70% of TCPA cases are now filed as class actions, per litigation analysis from TransUnion, and the statute of limitations runs four years — meaning every campaign you launch today stays live as potential litigation for years. Eric Troutman, one of the most-cited TCPA attorneys, has called the statute the biggest "cash cow" in the history of litigation.

Here's the part that catches most businesses off guard: the liability rests with you, not your vendors. If a lead seller generated the contact or a provider ran the outreach, courts and regulators still hold the business making the outreach responsible when consent turns out to be invalid. The brand on the message is the brand on the lawsuit.

That makes disclosure accuracy a board-level concern, not a marketing-line item. It also changes how you should evaluate any growth partner — including how we at Worqd approach our own B2B outreach, where permission-aware, personalized contact is the baseline rather than a template blast.

Before signing with any provider, check their compliance practices against these markers:

  • Do they keep timestamped, traceable consent records — the exact language shown, when it was collected, and proof a real human submitted the form? The burden of proof falls on you in a TCPA lawsuit.
  • Do they honor opt-outs in "any reasonable manner" within 10 business days, not just keyword replies like STOP? The FCC's Expanded Revocation Rule has required this since April 11, 2025.
  • Is their consent language clear and conspicuous, near the submit button, with no pre-checked boxes? Pre-checked boxes do not qualify as valid consent.
  • Do they retain consent records for at least five years — beyond the four-year statute of limitations?

Vague disclosures fail precisely because they're vague. Consent language that doesn't clearly identify your business, doesn't state what the consumer is agreeing to, or buries the terms below the fold invites the argument that consent was never valid at all. And once consent fails, every message built on it becomes a separate violation. Before you trust any partner with your outreach, ask to see the exact disclosure language they use — and where it sits on the page.

The Disclosures TCPA Requires, By Channel

A single consent form with a missing disclosure can invalidate every call and text that follows it — at $500 to $1,500 per violation, with no cap on total penalties, the math gets ugly fast. Here is exactly what the TCPA requires you to disclose, channel by channel.

On consent forms, the language must be "clear and conspicuous," placed near the submit button, and free from misleading wording, according to ActiveProspect's consent guidance. Three elements are non-negotiable:

  • The specific business (and any affiliates or partners) the consumer is agreeing to hear from
  • An acknowledgment that consent is not a condition of purchase
  • An unchecked opt-in box — pre-checked boxes do not qualify as valid consent

In every marketing message, regardless of channel, you must identify your business and include opt-out instructions, per IgniteSMS's compliance guide.

On calls, some states go beyond the federal baseline. Connecticut requires callers to disclose their business identity, the purpose of the call, and a contact method at the beginning of each call, with fines of $500–$1,000 per violation, as ClickPoint's state regulations overview details. California adds disclosure requirements when calls are recorded or placed using automatic dialing systems.

On texts, opt-out instructions are mandatory in every message. Since April 11, 2025, the FCC's Expanded Revocation Rule requires businesses to honor revocation in "any reasonable manner" within 10 business days — not just keyword replies like "STOP," per the FCC's public notice and Drips's rule-change breakdown. A message like "no more texts!" counts. After an opt-out, a one-time confirmation text must arrive within 5 minutes and contain no marketing content.

Two clarifications worth knowing. First, email falls under CAN-SPAM, not the TCPA — that law requires opt-out mechanisms, accurate sender information, and truthful subject lines, with fines up to $46,517 per non-compliant email. Second, "this call may be recorded" is not a TCPA disclosure at all — it relates to state recording-consent law and the federal Wiretap Act, as RecordingLaw.com explains.

Because liability rests with the business making the outreach — not the vendor — it's worth asking any growth partner how they handle disclosures and opt-out recognition. At Worqd, our own booking funnel requires explicit, unambiguous consent before anyone is contacted, and our outreach systems are built to recognize real-world language rather than keyword triggers alone.

What Changed in 2025: Opt-Outs, Revocation, and the One-to-One Rule

If you read a TCPA compliance guide written in early 2025, some of what it tells you is already wrong. The rules around consent and opt-outs shifted twice in the first half of 2025 alone, and outdated guidance is still circulating — which means any provider you work with needs to be checked against the rules as they stand today, not as they were described last year.

The one-to-one consent rule never took effect. The FCC's rule requiring separate consent for each individual seller was vacated by the Eleventh Circuit on January 24, 2025 — days before its January 27 implementation date — as legal experts have documented. The prior, broader standard now applies: a single written consent can cover multiple sellers, provided the restored consent definition is met — the disclosure must clearly and unmistakably authorize contact, including on behalf of named affiliates or partners if it says so.

Here's the problem: at least one widely-read vendor guide still describes the one-to-one rule as effective January 27, 2025, as this outdated article shows. That's exactly why you can't take a provider's compliance claims at face value. Ask them what consent standard they operate under, and verify it against the current text of 47 C.F.R. § 64.1200.

The second major shift is the Expanded Revocation Rule, effective April 11, 2025. Per the FCC's public notice and compliance analysis, businesses must now honor opt-outs given "in any reasonable manner" within 10 business days. That includes natural-language messages like "no more texts!" — not just the standard keywords. As Drips puts it bluntly: relying on keyword prompts like "Reply STOP to end" is risky.

What this means in practice for your outreach systems:

  • Opt-out recognition must go beyond STOP, QUIT, END, and CANCEL — it needs to catch real-world phrasing and even wrong-recipient replies like "I'm not Mary."
  • Revocation must be processed within 10 business days, with a one-time confirmation text sent within 5 minutes and containing no marketing content.
  • Opt-out data must sync across every connected system, so a contact who revokes with one message isn't contacted through another channel.

The stakes make the diligence worthwhile. Violations run $500 to $1,500 each with no cap on total penalties, and nearly 70% of TCPA cases are filed as class actions, according to TransUnion's legal panel. Liability sits with the business making the outreach, not the vendor.

This is why, when Worqd runs outreach or reactivates old leads for clients, the opt-out handling and consent documentation behind every campaign are checked against the rules as they exist now — because a provider following last year's playbook is a liability you'll pay for, not them.

How to Check a Provider's Compliance Practices Before You Hire Them

When evaluating outreach vendors, ensuring compliance with the Telephone Consumer Protection Act (TCPA) is crucial. The TCPA mandates specific disclosures that vary by outreach channel, consent type, and increasingly, by state law. This complexity makes it essential to scrutinize a provider's compliance practices thoroughly. Here’s how to check a provider’s compliance practices before you hire them.

Ensure that any outreach provider documents consent with timestamped, traceable records. According to industry research, the burden of proof lies with the business in TCPA lawsuits. Therefore, it's vital to verify that consent records include the exact language shown, timestamp, URL/platform of collection, evidence of human submission, and form fields submitted. Additionally, consent records should be retained for at least five years, aligning with the TCPA's statute of limitations. For instance, when Worqd performs B2B outreach, it requires explicit consent with detailed disclosures.

Verify that opt-out handling goes beyond keyword recognition. Effective April 11, 2025, businesses must honor consent revocation in "any reasonable manner" within 10 business days. Messages like "no more texts!" or "I'm not Mary" should be treated as opt-outs, not just standard keywords like "STOP." This requires outreach technology that recognizes real-world language and syncs opt-out data across all connected systems within the stipulated timeframe. For instance, Worqd's AI SDR systems are designed to handle natural-language opt-outs efficiently.

Include the required disclosure elements in every marketing message and consent form. Every marketing message must identify the business and include opt-out instructions. Consent language must be clear and conspicuous, placed near the submission button, free from misleading wording, and must include acknowledgment that consent is not a condition of purchase. Pre-checked boxes do not qualify. For example, Worqd's booking funnel already requires explicit consent, which aligns with the standalone opt-in requirement.

Treat state-level disclosure rules as additive to federal TCPA requirements. State laws like Connecticut’s requirement to identify the business, state the purpose of the call, and provide a contact method at the beginning of each call must be considered. California requires disclosure when recording calls or using automatic dialing systems. Florida restricts calling hours to 8am–8pm. Since Worqd serves clients across the US, outreach programs must comply with the strictest applicable state rules, not just federal TCPA.

Monitor the regulatory landscape. The rules have changed multiple times in the last three years, and the FCC may revisit them. According to regulatory guidance, the one-to-one consent rule was vacated on January 24, 2025, and the prior standard was restored. Compliance strategies should remain agile. Any claims made in marketing materials should be current and verified against the actual text of 47 C.F.R. § 64.1200. For example, Worqd's compliance practices are continually updated to reflect the latest regulatory changes.

By following these steps, you can ensure that your outreach efforts are compliant with the TCPA and minimize the risk of costly penalties and lawsuits. The stakes are high: TCPA violations cost $500 to $1,500 per call or text, with no cap on total penalties. A campaign to 5,000 contacts without consent can create $2.5M–$7.5M in exposure. Therefore, it's crucial to partner with a provider like Worqd that prioritizes compliance and keeps up with the latest regulatory changes. If your business needs to boost demand and ensure faster follow-up, book a growth call today.

Frequently Asked Questions

What disclosures does the TCPA actually require on a consent form?
Your consent language must be clear and conspicuous, placed near the submit button, and identify the specific business (plus any affiliates or partners) the consumer is agreeing to hear from. It must also acknowledge that consent is not a condition of purchase, and the opt-in box must be unchecked — pre-checked boxes do not qualify as valid consent.
How much can a TCPA violation actually cost my business?
Violations run $500 to $1,500 per call or text with no cap on total penalties, so a 5,000-contact campaign without valid consent creates $2.5M–$7.5M in exposure. Nearly 70% of TCPA cases are filed as class actions, and the statute of limitations runs four years, per TransUnion's litigation analysis.
If my lead vendor or outreach provider messed up the consent, am I still liable?
Yes. Courts and regulators hold the business making the outreach responsible when consent turns out to be invalid — the brand on the message is the brand on the lawsuit, and compliance guidance confirms the burden of proof falls on you. That's why you should ask any provider to show their exact disclosure language and timestamped consent records before signing.
Is the FCC's one-to-one consent rule still in effect in 2025?
No. The rule requiring separate consent for each individual seller was vacated by the Eleventh Circuit on January 24, 2025, days before its January 27 implementation date, and the prior broader standard was restored — a single written consent can cover multiple sellers if the disclosure clearly authorizes it, per RecordingLaw.com's analysis. Some vendor guides still describe the rule as active, so verify any provider's claims against the current text of 47 C.F.R. § 64.1200.
Do I have to honor opt-outs beyond replies like 'STOP'?
Yes. Since the FCC's Expanded Revocation Rule took effect April 11, 2025, you must honor revocation in "any reasonable manner" within 10 business days — a message like "no more texts!" or even "I'm not Mary" counts as an opt-out, per the FCC's public notice. After an opt-out, a one-time confirmation text must arrive within 5 minutes and contain no marketing content.
Does saying 'this call may be recorded' satisfy TCPA disclosure rules?
No — that's a common misconception. The recording disclosure relates to state recording-consent law and the federal Wiretap Act, not the TCPA's calling and texting restrictions, as RecordingLaw.com explains. Your actual TCPA obligations are identifying your business and providing opt-out instructions in every marketing message, plus any state-specific rules like Connecticut's requirement to state the call's purpose upfront.

Avoiding the Pitfalls: Ensuring TCPA Compliance in Your Outreach

The TCPA isn’t just a legal formality—it’s a financial safeguard. Vague disclosures can turn a routine campaign into a multimillion-dollar liability, with penalties up to $1,500 per violation and class-action risks that amplify the stakes. Clear, channel-specific disclosures—whether on consent forms, calls, or texts—are non-negotiable, and the burden of proof rests squarely on your business, not your vendors. By rigorously vetting providers for transparent consent practices, real-time opt-out handling, and compliance with evolving rules like the 2025 Expanded Revocation Rule, you mitigate risks while maintaining trust. For businesses like Worqd, this means embedding compliance into every outreach step, from personalized B2B engagement to AI-driven follow-up. The next move? Audit your current partners against these standards, verify their consent documentation processes, and ensure their systems adapt to regulatory shifts. Protect your growth—and your bottom line—by treating TCPA compliance not as a checkbox, but as a strategic imperative. Learn how to evaluate provider compliance practices today.

Want help putting this into action?

Book a Growth Call
TopicsTCPA disclosure requirementsTCPA consent form languageTCPA compliance for outreachTCPA opt-out rules 2025TCPA violation penaltiescheck vendor TCPA complianceTCPA text message compliance

Stay in the Loop