Written by: Matt Beucler, CEO, Plura AI
Updated September 2026
Key Takeaways
- TCPA penalties reach $500 per violation or $1,500 for willful conduct, with no statutory cap, so exposure can reach millions across private lawsuits, FCC forfeitures, FTC penalties, and state actions.
- Each call or text counts as a separate violation, so a single non-compliant campaign can create massive statutory exposure without proving actual harm.
- Common violations include missing prior express written consent, DNC scrubbing failures, opt-out delays, abandoned calls, quiet-hour breaches, and reassigned-number issues.
- The four-year statute of limitations lets exposure accumulate over time, so long-term consent and suppression record retention becomes essential.
- Plura AI’s carrier-grade compliance engine automates DNC scrubbing, consent logging, and quiet-hours enforcement on every outbound contact, and you can see how it works.
TCPA Statutory Penalties Under 47 U.S.C. § 227
The Telephone Consumer Protection Act (TCPA), codified at 47 U.S.C. § 227, creates a private right of action with statutory damages of $500 per violation, rising to $1,500 per violation if a court finds the conduct was willful or knowing.2 These amounts apply to each individual call, text message, or fax, not per phone number or per campaign.
The treble damages standard. Courts may increase damages to $1,500 only when the violation was “willful or knowing.” The defendant does not need to know the TCPA existed or that their conduct violated it, only that they were making the calls or sending the texts that turned out to be unlawful. Most intentional marketing campaigns with inadequate consent records present a strong risk of treble damages under this standard.
The math that matters. There is no statutory cap on total damages, and each call or text counts as a separate violation. A single automated campaign placing 10,000 calls to non-consenting numbers creates statutory exposure of:
- $5 million at the $500 base rate
- $15 million if a court finds willful conduct
Plaintiffs do not need to prove actual harm. Receiving the unwanted call or text is sufficient injury under the statute, which makes TCPA class actions particularly attractive to plaintiffs’ attorneys.
See carrier-level TCPA enforcement in a live Plura AI demo.
FCC Enforcement and Forfeiture Penalties
The FCC pursues its own enforcement track under Section 503(b) of the Communications Act, separate from private lawsuits. As of 2026, the maximum forfeiture is $25,132 per day for a continuing violation and $188,491 for a single act or failure to act.
How the FCC calculates forfeitures. The FCC starts from a base forfeiture amount and adjusts it based on several factors: the degree of willfulness, the history of prior offenses, the ability to pay, and whether the party took remedial steps. The FCC can aggregate penalties across many individual calls with no statutory cap on total violations. In 2022, the FCC proposed a $299,997,000 forfeiture against an auto warranty robocall operation, which shows that agency enforcement can rival or exceed private litigation exposure.
FCC forfeitures run concurrently with private lawsuits, meaning a company can settle a class action and still face an FCC Notice of Apparent Liability for the same conduct.
FTC and State Attorney General Penalties
The FTC enforces the Telemarketing Sales Rule (TSR), codified at 16 CFR Part 310, with civil penalties of up to $51,744 per call (2024 adjusted rate).2 Each individual call can be a separate violation, with no per-campaign cap. The FTC also seeks injunctive relief and disgorgement of profits, so exposure extends beyond a simple per-call fine.
State attorneys general can enforce the TCPA directly and pursue additional penalties under state mini-TCPA statutes. Florida’s Telephone Solicitation Act (FTSA), for example, creates its own private right of action with $500 per call damages and uses a broader autodialer definition than post-Duguid federal law.
Class Action Exposure with Real Settlement Benchmarks
Class actions represent the primary financial threat for high-volume callers because per-call damages multiply across every affected consumer. A campaign that sent one million illegal texts exposes a company to $500 million in statutory liability before any willfulness finding.3 The table below shows real settlement amounts that illustrate how these exposures play out in practice.
| Case | Settlement Amount | Allegations |
|---|---|---|
| Dish Network (2017) | $280 million judgment | Do Not Call violations |
| Sirius XM Radio (2026) | $28 million | Calls to DNC-registered numbers |
| Realogy / Coldwell Banker | $20 million | Unsolicited cold calls |
| Portfolio Recovery Associates | $18 million | Calls to wrong-number recipients |
| Papa John’s (2018) | $16.5 million | Unsolicited marketing texts |
Settlements typically resolve for a fraction of full statutory exposure, often $20 to $150 per class member, because defendants pay to avoid the risk of a larger judgment and litigation costs. These per-person amounts look modest, yet the settlement totals still reach eight and nine figures because the underlying exposure is so large.
Operational Mistakes That Commonly Trigger TCPA Penalties
The most frequently litigated TCPA violations include:
- Autodialed or prerecorded calls and texts to cell phones without prior express written consent
- Calls to numbers on the National Do Not Call Registry, which holds over 240 million registered numbers and requires scrubbing at least every 31 days
- Failure to honor opt-out requests within 10 business days under current FCC rules
- Abandoned calls, defined as failing to connect a live agent within 2 seconds of the called party answering, exceeding a 3% abandonment rate per campaign
- Quiet-hour violations, meaning telemarketing calls before 8 a.m. or after 9 p.m. in the recipient’s local time zone
- Reassigned numbers, where the prior subscriber consented but the number has since been reassigned to a new owner
Bad consent records are the single most common cause of TCPA exposure, followed by DNC failures and opt-out failures. Purchased or rented lead lists, weak suppression-list controls, and stale opt-out handling sit at the operational root of most enforcement actions.
Statute of Limitations and How to Quantify Exposure
The federal statute of limitations for TCPA claims is four years under 28 U.S.C. § 1658. A lawsuit filed today can include violating calls or texts sent up to four years earlier. Consent and suppression records should be retained at least that long.
Calculating potential exposure follows a straightforward formula. Multiply the number of violating calls or texts by the per-violation amount to estimate total exposure.
A practical example: an outbound sales team making 10,000 calls per month on a list with 5% DNC contamination generates 500 potential violations per month, or 6,000 per year. At the $500 base rate, annual exposure is $3 million. If a court finds willful conduct, exposure triples to $9 million. Over the four-year statute of limitations, total exposure reaches $36 million.
Watch a live demo of real-time DNC scrubbing and consent logging with Plura AI.
Key TCPA and FCC Developments in 2026
Several significant developments shape the TCPA landscape as of September 2026:
- One-to-one consent rule vacated. The Eleventh Circuit in Insurance Marketing Coalition Ltd. v. FCC, 127 F.4th 303 (11th Cir. 2025), struck down the FCC’s one-to-one consent rule, holding that the agency exceeded its statutory authority. The pre-2023 prior express written consent standard applies.
- Seventh Circuit narrows DNC text claims. In Steidinger v. Blackstone Medical Services, 182 F.4th 532 (7th Cir. July 2026), the court held that text messages are not “telephone calls” under § 227(c)(5), limiting DNC-based text claims in Illinois, Indiana, and Wisconsin.
- Fifth Circuit invalidates written consent regulation. In Bradford v. Sovereign Pest Control of TX, Inc., 167 F.4th 809 (5th Cir. March 2026), the court held that only undefined “prior express consent” is required regardless of whether the call is telemarketing.
- Supreme Court limits FCC deference. McLaughlin Chiropractic Associates, Inc. v. McKesson Corp., 606 U.S. 146 (2025), held that courts must independently interpret the TCPA rather than deferring to FCC orders.
- AI-generated voices covered. The FCC confirmed that calls using AI-generated voices are “artificial or prerecorded” voices under the TCPA, requiring prior express written consent for telemarketing calls to cell phones.
- FCC penalty freeze. Civil monetary penalties remain frozen at 2025 levels for 2026 due to the federal government shutdown and the resulting unavailability of October 2025 CPI data.
These 2026 rulings and the frozen penalty levels keep per-violation amounts high while courts scrutinize consent standards, so proactive, infrastructure-level controls matter more than ever.
Mitigating TCPA Risk with Plura AI’s Enforcement Layer
Quantifying exposure is the first step, but mitigation requires more than manual processes or bolt-on checklists. It demands infrastructure-level compliance enforcement that operates on every outbound contact before it leaves the network. Plura AI’s compliance engine functions as a first-class layer of the platform and enforces TCPA-related rules on each call or text at the carrier level.
1Plura’s compliance features include:
- Real-time DNC scrubbing. Every outbound contact is checked against federal and state DNC registries before dial. Non-compliant numbers are blocked before the first attempt.
- Immutable consent logging. Consent records are timestamped, stored, and audit-ready, with express written consent tracked per contact, including the specific disclosure language and channel.
- Automated quiet-hours enforcement. State and federal calling-window restrictions apply automatically through time-zone detection on the contact.
- TCPA-litigator screening. Numbers associated with known TCPA litigants are filtered before dial, which reduces serial-litigant exposure.
- 100% U.S. infrastructure. Plura runs on its own FCC-licensed carrier with voice origination, model hosting, and data storage on domestic infrastructure.
Plura supports compliance through these built-in controls, and customers remain responsible for their own regulatory obligations and consent practices. High-volume operators gain a consistent enforcement layer that applies the same rules on every campaign, across every team.

The platform also powers AI Predictive Dialer campaigns and AI SMS outreach with the same compliance layer applied to every contact, across every channel. Conversation intelligence surfaces audit-ready reporting in one click.
Compare plans and rates side by side.
Run your numbers through Plura’s ROI calculator to evaluate the cost-benefit of compliance automation.3
Schedule a demo to see carrier-grade TCPA enforcement in action.
FAQ: TCPA Penalties and Multi-Track Enforcement
What are the most common TCPA violations?
The most frequently litigated violations include autodialed or prerecorded calls and texts to cell phones without prior express written consent, calls to numbers on the National Do Not Call Registry, failure to honor opt-out requests, abandoned calls exceeding a 3% rate per campaign, and quiet-hour violations before 8 a.m. or after 9 p.m. in the recipient’s local time zone. Reassigned numbers, where a prior subscriber consented but the number has since changed hands, are also a common source of exposure. Weak or incomplete consent records sit at the center of most of these issues.
What is the statute of limitations on a TCPA claim?
The federal statute of limitations for TCPA claims is four years under 28 U.S.C. § 1658, the federal catch-all limitations period. The clock runs from the date of each individual violation, not from when the plaintiff discovered it. A lawsuit filed today can include violating calls or texts sent up to four years earlier, so consent records, DNC scrub logs, and opt-out logs need retention practices that match that window. Consult qualified counsel for guidance on record-keeping policies for your specific situation.
How much is a TCPA class action settlement?
TCPA class action settlements range from millions to hundreds of millions of dollars. Examples include Dish Network’s $280 million federal court judgment for Do Not Call violations, Sirius XM’s $28 million settlement fund for calls to DNC-registered numbers, and Realogy’s $20 million settlement for unsolicited cold calls. Individual payouts to class members typically range from $20 to $150 per person, because settlements resolve for a fraction of full statutory exposure. The total settlement amounts are large because the underlying per-call exposure, at the $500 to $1,500 per-violation amounts discussed earlier, multiplies across every affected consumer.
What is the difference between TCPA private damages and FCC forfeitures?
TCPA private damages of $500 to $1,500 per violation are statutory amounts that consumers seek through lawsuits under 47 U.S.C. § 227(b)(3). These are not agency-imposed fines. FCC forfeitures are civil penalties assessed by the FCC Enforcement Bureau under Section 503(b) of the Communications Act, with a maximum of $25,132 per day for a continuing violation and $188,491 for a single act as of 2026. These two tracks are independent and can apply to the same conduct at the same time. FTC Telemarketing Sales Rule penalties, at up to $51,744 per call, represent a third separate track enforced by the FTC. Consulting qualified counsel helps clarify how these tracks may interact for a specific fact pattern.
How does Plura AI support TCPA compliance for high-volume operators?
Plura AI’s compliance engine operates as a first-class layer of the platform. Every outbound contact is checked against federal and state DNC registries in real time before dial. Consent records are timestamped and stored in an immutable ledger. Quiet-hours restrictions apply automatically through time-zone detection. TCPA-litigator screening filters known serial litigants before dial. The compliance dashboard exports audit-ready reports in one click. Because Plura operates its own FCC-licensed carrier, these controls apply at the carrier level before a call or text leaves the network, while customers remain responsible for their own regulatory obligations and consent practices.
1 Plura AI maintains SOC 2, HIPAA, ISO, and GDPR posture as part of its platform infrastructure. References to compliance frameworks in this article describe Plura’s platform capabilities and do not constitute a guarantee that any customer using Plura will themselves be compliant with applicable laws or standards. Customers remain solely responsible for their own regulatory obligations, certifications, consent management, recordkeeping, and the claims they make to their own end users. Consult qualified legal counsel for guidance specific to your use case.
2 This article describes regulatory frameworks at a general level and does not constitute legal advice. Laws and regulations vary by jurisdiction, change over time, and apply differently depending on facts and circumstances. Readers should consult qualified legal counsel before making compliance decisions.
3 Performance figures, customer outcomes, and industry statistics referenced in this article are drawn from cited third-party sources or Plura customer case studies. Individual results vary based on implementation, use case, industry, audience, and execution. Past or aggregate performance is not a guarantee of future results.
This article is provided for informational purposes only and reflects Plura AI’s understanding at the time of publication. Product capabilities, integrations, and specifications are subject to change. For the most current information, visit plura.ai.
This article was produced with the assistance of AI tools and reviewed by Plura AI prior to publication.