TCPA Compliance Checklist 2026: The Complete Guide

TCPA Compliance Checklist 2026: The Complete Guide

ON THIS PAGE

Written by: Matt Beucler, CEO, Plura AI

Updated September 2026

Key Takeaways

  • The 2026 TCPA checklist centers on seven operational steps: prior express written consent, 31-day DNC scrubbing, Reassigned Numbers Database checks, local-time calling hours, immediate opt-out processing, STIR/SHAKEN caller ID, and five-year audit trails.
  • Statutory damages of $500–$1,500 per violation create multimillion-dollar exposure.2 In 2025, 2,588 lawsuits were filed, and settlements often reached eight and nine figures.3
  • Recent court rulings such as McLaughlin and Bradford, along with the FCC’s 2026 NPRM on offshore centers and AI voice agents, shifted how high-volume operators manage compliance.
  • State mini-TCPA laws in at least 12 states add stricter hours, separate DNC lists, and higher penalties that stack on top of federal damages.
  • Plura AI automates real-time DNC scrubbing, TCPA-litigator screening, automated quiet hours, and immutable consent logging on every outbound contact. See how the platform enforces compliance at scale.

TCPA Compliance Checklist: 7 Steps for High-Volume Operators

  1. Obtain express written consent – document proof with timestamps, source IP, and exact disclosure language.
  2. Scrub against the National DNC Registry – at least every 31 days under the FTC’s safe harbor rule.
  3. Check the Reassigned Numbers Database (RND) – avoid calling numbers that changed owners after consent.
  4. Honor calling hours – 8 a.m. to 9 p.m. local time at the called party’s location, with stricter state variations.
  5. Process opt-outs immediately – across voice and SMS, within 10 business days under FCC rules.
  6. Transmit accurate caller ID – use STIR/SHAKEN authentication and branded caller ID on outbound calls.
  7. Maintain audit trails and records – retain consent records, DNC scrub logs, call recordings, and opt-out records for at least five years.

Consent: Written, Clear, and Documented

The FCC’s 2012 rule (47 C.F.R. § 64.1200(f)(9)) defines prior express written consent for telemarketing calls and texts.2 The rule describes a written agreement with the consumer’s signature, specific authorization for autodialed or prerecorded calls and texts, the phone number authorized, and a clear disclosure that consent is not a condition of purchase. Electronic signatures are valid under the E-SIGN Act (15 U.S.C. § 7001).

Each consent record works best when it captures a server-side UTC timestamp, the IP address, the exact disclosure language shown at opt-in, a form version identifier, and the specific phone number authorized. Courts require the exact disclosure language shown at the time of opt-in, not the current form version. Version-control forms and store a rendered snapshot with every consent event.

In February 2026, the Fifth Circuit’s Bradford v. Sovereign Pest Control decision held that the TCPA does not require written consent within that circuit, relying on the Supreme Court’s elimination of Chevron deference in Loper Bright. The court still emphasized that consent must be clear, direct, unequivocal, and carefully documented. This ruling applies only within the Fifth Circuit. Other circuits and state laws may still require written consent, so leaders should consult qualified counsel on how this affects specific operations.

For third-party leads, require the vendor’s full consent record for each lead as a condition of payment. That record should include timestamp, IP, and form language. Any lead without a complete consent record belongs in suppression instead of the dialing queue. A contractual indemnification clause shifts financial risk but does not remove the plaintiff’s claim against your brand.

Plura AI logs consent records immutably so they remain timestamped, version-controlled, and audit-ready.

Screenshot of Plura’s fully compliant AI communications platform showing business registration and phone number provisioning workflows for AI Voice, SMS, RCS, and Webchat communication automation.
Plura’s FCC-licensed AI communications platform simplifies compliant business registration and phone number provisioning for AI Voice, SMS, RCS, and Webchat workflows.

DNC Scrubbing: National, Internal, and Reassigned Numbers

The National DNC Registry requires scrubbing at least every 31 days. The FTC shortened this from quarterly effective January 1, 2005. Each seller needs its own Subscription Account Number. Internal do-not-call lists remain a separate obligation with no exemptions.

The FCC’s Reassigned Numbers Database (RND), live since November 2021, lets callers query a number plus the date consent was obtained. A “No” response provides a safe harbor for that specific call. A “Yes” response eliminates the safe harbor. “No Data” provides no safe harbor. Roughly 35 million U.S. phone numbers are reassigned each year, so about 100,000 numbers get new owners daily.3 Consent attaches to the person, not the digits.

The RND updates monthly, with new disconnection data uploaded on the 16th of each month. To keep an active safe harbor, scrub lists at least every 31 days, ideally close to the 16th. The safe harbor assumes prior consent before reassignment, a query of the most recent RND data, a “No” response, and that response later proving inaccurate. The Congressional Research Service’s May 2026 report R48941 notes there is no mandatory RND query requirement for robotexts. Leaders should consult qualified counsel on how text messaging practices interact with RND use.

Plura enforces real-time DNC scrubbing against federal and state registries before every dial so non-compliant numbers are blocked before the first attempt. The platform also integrates with the Reassigned Numbers Database as part of its validation layer.

Calling Hours: Local Time and State Variations

Federal calling hours run 8 a.m. to 9 p.m. in the called party’s local time zone, not the caller’s office time zone. State mini-TCPA laws impose stricter windows. Florida’s FTSA restricts calls to 8 a.m. to 8 p.m. local time. Oklahoma restricts calls to 9 a.m. to 8 p.m. Maryland and Oregon also cap at 8 p.m.

Florida’s FTSA keys off the number’s area code, not the consumer’s physical location. A 305 number whose owner moved to Georgia still poses FTSA risk. That is why automated systems must enforce quiet hours through time-zone detection, as Plura does on every contact.

Opt-Outs: Immediate Processing Across Channels

The FCC’s April 2025 revocation rules shortened the opt-out processing window to 10 business days and allow consumers to revoke consent by any reasonable means such as verbal requests, text replies, or web forms. Standard keywords (STOP, QUIT, END, REVOKE, OPT OUT, CANCEL, UNSUBSCRIBE) are automatically effective. Nonstandard phrasing creates a rebuttable presumption of revocation.

Revocation crosses channels, so an opt-out sent by text also ends calls, and the reverse applies. A 48-hour gap between receiving an opt-out and suppressing the number means every call in that window is a possible violation at $500 per call, up to $1,500 for willful violations.

Plura processes opt-outs immediately and shares suppression across voice, AI SMS, RCS, and AI webchat channels.

Caller ID and Identification: STIR/SHAKEN and Branded Caller ID

STIR/SHAKEN is the call authentication framework that verifies caller ID has not been spoofed. As of early 2026, only about 45% of total call traffic is fully signed. The Truth in Caller ID Act describes spoofing caller ID as a criminal offense. Branded caller ID, issued at the carrier level, presents your company name and reason for calling instead of “Spam Likely” or an unfamiliar number.

Plura issues branded caller ID directly through its FCC-licensed carrier and authenticates every outbound call with STIR/SHAKEN at the carrier level. Many AI voice platforms built on top of third-party CPaaS providers cannot issue branded caller ID under their own identity because they do not own the carrier. Plura owns the carrier relationship and controls that layer.

See carrier-level caller ID in action with a live demo and review how it affects answer rates and complaint volume.

Vendor and Lead-Source Due Diligence

Courts consistently hold brands vicariously liable for TCPA violations committed by third-party vendors under agency principles such as actual authority, apparent authority, and ratification. Before purchasing leads, require the vendor’s full consent record for each lead, including timestamp, IP, and form language. Secure a written agreement where the vendor represents that it collected valid TCPA-consent and indemnifies the buyer, and verify that the opt-in disclosure named your company.

The FCC’s one-to-one consent rule was vacated by the Eleventh Circuit in January 2025. The underlying PEWC standard still focuses on consent that is specific to the seller. General consent to “marketing partners” is being attacked in court as insufficient.

Audit vendors regularly. Pull a sample of consent records and verify that every field is populated, the form version matches an archived version, and the IP address geolocates correctly. Indemnification clauses shift financial risk but do not remove your role as the party that placed the call.

Plura screens for known TCPA litigators on every outbound contact through its AI Predictive Dialer, which adds a protection layer that manual vendor audits cannot match at scale.

Plura Predictive Dialer dashboard displaying AI-powered outbound call pacing, transfer analysis, and dialing performance insights.
Plura Predictive Dialer automates outbound calling with AI-powered pacing, transfer optimization, and real-time performance analytics.

Audit Trails and Recordkeeping

Retain consent records, DNC scrub logs, call recordings, opt-out records, and campaign details. The federal statute of limitations for TCPA claims is four years under 28 U.S.C. § 1658. The FTC’s Telemarketing Sales Rule describes a five-year retention period for consent records. Some states describe longer periods. Many operators choose to retain records at least five years from the date of last contact.

Records must be admissible as business records under Federal Rule of Evidence 803(6). That standard focuses on records made at or near the time of opt-in, kept in the ordinary course of business, and authenticated by a records custodian. A consent record that cannot be produced functions the same as no consent at all.

Plura exports audit-ready reports in one click, including consent records, DNC scrub logs, call recordings, and opt-out records, through its conversation intelligence and compliance dashboard.

Plura Security & Compliance dashboard highlighting SOC 2, ISO, and GDPR standards with secure trust verification management.
Plura Security & Compliance supports SOC 2, ISO, and GDPR standards with trust registration, verification management, and secure AI communications.1

2026 Update: FCC NPRM and AI Voice Agents

Beyond recordkeeping, the FCC’s 2026 rulemaking activity introduces new considerations for high-volume operators. The FCC’s NPRM (CG Docket No. 26-52) proposes capping offshore customer-service calls at 30% and limiting offshore handling of sensitive consumer data such as passwords, multi-factor authentication, social security numbers, and banking or card data. Companion legislation, the Keep Call Centers in America Act (S.2495) and the Foreign Robocall Elimination Act (S.2666), extends the regulatory perimeter. State laws in New York, New Jersey, Connecticut, Missouri, and Florida already restrict offshore handling of medical, financial, and consumer data.

AI voice agents fall under TCPA rules. The FCC’s February 2024 Declaratory Ruling confirmed that AI-generated voices count as “artificial” voices under 47 U.S.C. § 227(b)(1)(B), which triggers prior express consent requirements for AI-voiced calls. The FCC’s NPRM 24-84 proposes requiring callers to disclose at the beginning of each call that the call uses AI-generated technology. As of September 2026, this remains a proposal rather than a final rule. Leaders should consult qualified counsel on how pending rules may affect their operations.

Plura runs on 100% U.S. infrastructure by architecture. Voice origination, model hosting, data storage, and call recording all sit on domestic infrastructure, which supports customer compliance with emerging offshore restrictions.

How State Mini-TCPA Laws Affect Your Checklist

At least 12 states, including Florida, Oklahoma, Washington, Indiana, Texas, Maryland, and Oregon, describe stricter requirements than the federal TCPA. State statutory damages can stack on top of TCPA’s $500 and $1,500 per-violation federal damages because the claims arise under different statutes.

Florida’s FTSA describes consent language that specifically references automated telephone technology. Oregon’s HB 3865, effective January 1, 2026, restricts contact hours to 8 a.m. to 8 p.m. and limits daily calls to three per consumer. Texas SB 140, effective September 1, 2025, expanded “telephone solicitation” to cover texts and images and introduced a private right of action with statutory damages up to $5,000 per violation. At least 14 states maintain their own do-not-call lists separate from the federal National DNC Registry.

For high-volume operators reaching consumers across multiple states, the strictest applicable rule often governs each contact in practice. Plura’s compliance engine pre-loads more than 50 state rule sets and enforces them automatically through time-zone detection on every outbound contact.

Frequently Asked Questions

What are common TCPA violations?

Common TCPA violations include calling or texting without prior express written consent, calling numbers on the National DNC Registry, calling during restricted hours, failing to honor opt-outs within the required window, and transmitting inaccurate caller ID. Each violation carries $500 in statutory damages, which can increase to $1,500 for willful conduct under 47 U.S.C. § 227(b)(3). In class actions, per-violation damages multiply across every class member contact, so settlements often reach eight and nine figures.

What is the fine for a TCPA violation?

Statutory damages are $500 per violation and can increase to $1,500 for willful or knowing violations. There is no cap on total damages in a class action. A single campaign to 50,000 unconsented numbers creates $25 million to $75 million in exposure before any FCC administrative forfeiture penalties, which can reach $23,727 per violation in separate enforcement actions.3 Defense costs for a contested TCPA case can run $50,000 to $300,000 before trial.

How often must you scrub the DNC list?

Scrub at least every 31 days under the FTC’s Telemarketing Sales Rule, which tightened this from quarterly effective January 1, 2005. Each seller needs its own Subscription Account Number to access the National DNC Registry. Internal do-not-call lists are a separate obligation and must be honored within 10 business days of an opt-out request under current FCC rules. Some states, including Indiana and Texas, require scrubbing against their own state DNC lists within 30 days as well.

What is the FCC Reassigned Numbers Database?

The RND, live since November 2021 at reassigned.us, lets callers query whether a phone number has been reassigned since the date consent was obtained. A “No” response provides a safe harbor for that specific call. A “Yes” response eliminates the safe harbor. “No Data” provides no safe harbor either way. The database updates monthly on the 16th of each month. The RND’s scale was noted earlier, and consent attaches to the person, not the digits. Maine became the first state to reference RND use by statute in July 2024.

How do state mini-TCPA laws affect your checklist?

State mini-TCPA laws add tighter calling hours, separate do-not-call lists, higher penalties, and broader definitions of regulated technology. Florida’s FTSA restricts calls to 8 a.m. to 8 p.m. and describes consent language that specifically references automated telephone technology. Texas SB 140 expanded “telephone solicitation” to cover texts and images with damages up to $5,000 per violation. State damages stack on top of federal TCPA damages because the claims arise under different statutes. Operators that reach consumers in multiple states often apply the strictest applicable rule to each contact and work with qualified counsel on state-specific obligations.

Conclusion and Next Steps

TCPA compliance functions as an ongoing operational discipline, not a one-time project. The seven steps in this checklist, including consent documentation, DNC scrubbing, RND checks, calling hours, opt-outs, caller ID, and audit trails, need consistent enforcement on every outbound contact. Manual enforcement rarely scales for high-volume teams.

Plura AI enforces real-time DNC scrubbing, TCPA-litigator screening, automated quiet hours, and immutable consent logging on every outbound contact at the carrier level. The platform’s AI Predictive Dialer and AI SMS products run on 100% U.S. infrastructure by architecture. SOC 2, HIPAA, and ISO certification back the platform’s security posture.1 Compare plans and rates side by side, or use Plura’s ROI calculator to estimate cost savings in real time.

Book a live demo to see TCPA automation across channels and review how Plura supports compliance for high-volume outbound teams.


1 Plura AI maintains SOC 2, HIPAA, ISO, and GDPR posture as part of its platform infrastructure. References to compliance frameworks in this article describe Plura’s platform capabilities and do not constitute a guarantee that any customer using Plura will themselves be compliant with applicable laws or standards. Customers remain solely responsible for their own regulatory obligations, certifications, consent management, recordkeeping, and the claims they make to their own end users. Consult qualified legal counsel for guidance specific to your use case.

2 This article describes regulatory frameworks at a general level and does not constitute legal advice. Laws and regulations vary by jurisdiction, change over time, and apply differently depending on facts and circumstances. Readers should consult qualified legal counsel before making compliance decisions.

3 Performance figures, customer outcomes, and industry statistics referenced in this article are drawn from cited third-party sources or Plura customer case studies. Individual results vary based on implementation, use case, industry, audience, and execution. Past or aggregate performance is not a guarantee of future results.

This article is provided for informational purposes only and reflects Plura AI’s understanding at the time of publication. Product capabilities, integrations, and specifications are subject to change. For the most current information, visit plura.ai.

This article was produced with the assistance of AI tools and reviewed by Plura AI prior to publication.

Read Next

See how Plura AI transforms AI voice agents