Written by: Matt Beucler, CEO, Plura AI
Key Takeaways
- TCPA violations carry statutory damages of $500 per violation, trebled to $1,500 for willful or knowing violations, with no aggregate cap across class actions.2
- Private plaintiffs and the FCC enforce the TCPA on two independent tracks, creating separate exposure from statutory damages and civil forfeiture.
- Willful violations require proof of knowing or reckless conduct, not just volitional action, per the Seventh Circuit’s 2026 Hossfeld ruling.
- Operational controls like consent records, DNC scrubbing, and quiet-hours enforcement reduce liability on all enforcement tracks.
- Operational controls can be enforced at the platform level before dial, which reduces exposure from high-volume outbound campaigns.
How TCPA Damages Add Up
Under 47 U.S.C. § 227(b)(3), a private plaintiff may recover the greater of actual monetary loss or $500 per violation.2 If the court finds the violation willful or knowing, it may treble the award to up to $1,500 per violation. Statutory damages are uncapped and aggregate across a class.
TCPA violations can cost $500 to $1,500 per text or call, and the math scales fast because each contact is usually treated as a separate violation. A campaign that sends 1,000 unlawful texts produces $500,000 in exposure at the standard rate, and $1.5 million if a court finds the violations willful or knowing.3 Each call or text is typically treated as a separate violation, so exposure scales linearly with campaign volume. The $500 base award is strict liability. A plaintiff need not show intent, only that the defendant called a cell phone with an automatic telephone dialing system (ATDS) or prerecorded voice without consent, or called a number on the DNC (Do Not Call) registry.
The table below summarizes the statutory damages structure under § 227(b)(3).
| Violation Type | Statutory Damages Per Violation | Source |
|---|---|---|
| Standard violation | $500 | 47 U.S.C. § 227(b)(3) |
| Willful or knowing violation | Up to $1,500 (trebled) | 47 U.S.C. § 227(b)(3) |
| Aggregate cap | None, uncapped | 47 U.S.C. § 227(b)(3) |
See how the Compliance Engine enforces TCPA rules before dial.
How Courts Decide Willful TCPA Violations
Willfulness under the TCPA requires more than volitional conduct. The Seventh Circuit’s 2026 ruling in Hossfeld v. Allstate Insurance Co. (No. 25-1518, 7th Cir. 2026) held that TCPA treble damages require a knowing or reckless violation, not merely volitional conduct. The court also highlighted that documented compliance and consent records can be critical to defeating willfulness allegations.
The Seventh Circuit rejected the district court’s holding that “willful” in the TCPA context requires only that the violator’s acts be “volitional,” stating: “Volitional action is thus insufficient to trigger treble damages under the TCPA; we require reckless or knowing behavior.” The court adopted the Supreme Court’s standard from Safeco Insurance Co. of America v. Burr (551 U.S. 47 (2007)), defining reckless conduct as engaging in behavior that creates “an unjustifiably high risk of harm that is either known or so obvious that it should be known.”
The Seventh Circuit’s ruling makes proof of the caller’s mental state central to TCPA enhanced-damages claims, increasing the defense value of documented compliance and consent records. For businesses that relied on prior express consent, the ruling means consent disputes may still produce TCPA exposure if consent was deficient or revoked. Enhanced damages require proof of a knowing or reckless violation rather than mere calling after consent-based outreach. Consult qualified counsel for analysis of your specific facts and consent record practices.
Who Enforces The TCPA?
The TCPA is enforced on two tracks. Private plaintiffs bring statutory-damages actions under 47 U.S.C. § 227(b)(3). Separately, the FCC pursues civil forfeiture under 47 CFR § 1.80, a distinct enforcement track that operates independently of private litigation. State attorneys general also have concurrent authority under the TCPA and their own telemarketing statutes.
Under 47 CFR § 1.80(b)(2), forfeitures against common carriers are capped at $251,322 per violation or per day of a continuing violation. The maximum for any single act or failure to act is $2,513,215. That ceiling is materially higher than some other categories, which is why carrier-level TCPA enforcement can reach seven figures. The FCC initiates forfeiture by issuing a Notice of Apparent Liability (NAL) that identifies the specific provision violated, the nature of the conduct, and the proposed penalty amount. Recent FCC forfeiture settlements illustrate how this track operates in practice. The FCC reached a $1,050,000 forfeiture settlement with Verizon in 2024 over 911 outage violations, and announced a $13 million settlement with AT&T on September 17, 2024, resolving its investigation into a vendor cloud breach.4 Penalty amounts are calculated by reference to call volume and the nature of the underlying conduct.
The table below compares the two enforcement tracks side by side.
| Attribute | Private Statutory Damages | FCC Civil Forfeiture |
|---|---|---|
| Enforcer | Private plaintiffs | FCC |
| Multiplier | 1x or 3x (willful or knowing, per 47 U.S.C. § 227(b)(3)) | Per-violation schedule under 47 CFR § 1.80 |
| Cap | None, uncapped under 47 U.S.C. § 227(b)(3) | Statutory maximums per violation category under 47 CFR § 1.80 |
The DNC-Registry Penalty Distinction
The two-track model above covers § 227(b) claims. DNC-registry violations add a third set of figures that is often confused with the private statutory damages available under 47 U.S.C. § 227(b)(3). Conflating the two produces a misleading picture of total exposure.
The FTC (Federal Trade Commission) and FCC can each impose civil penalties of up to $53,088 per Do Not Call Registry violation, a cap that both agencies adjust annually for inflation under the Federal Civil Penalties Inflation Adjustment Act.2 This figure applies to agency enforcement actions, not to private lawsuits. Private plaintiffs pursuing DNC-registry claims proceed under 47 U.S.C. § 227(c)(5), which allows recovery of $500 per violating call, trebled to $1,500 for willful or knowing violations. The per-violation structure matches § 227(b)(3) but rests on a different statutory basis.
The FCC’s rules under TCPA Section 227(b) require prior express consent for autodialed or prerecorded calls to wireless numbers whether or not the number is on the DNC registry, creating a separate obligation from DNC registry rules. A number’s absence from the national registry does not authorize an autodialed marketing call to a cell phone. These are parallel obligations that apply independently. Consult qualified counsel to understand how each track applies to your specific calling practices.
What Happens If You Violate The TCPA?
Statutory damages aggregate across a class, and the uncapped nature of § 227(b)(3) makes volume the multiplier. A high-volume outbound operation can face class-wide exposure in the tens of millions from a single campaign.
The TCPA contains no statutory cap on aggregate damages. A single calling campaign can therefore produce class-wide exposure in the tens or hundreds of millions of dollars. Courts have approved TCPA settlements ranging from $2.5 million for small defendants to over $75 million for larger class actions. Strict liability means intent is not required for the base $500 award. The violation is the call itself.
Class certification can aggregate large volumes of allegedly unlawful calls or texts into a single lawsuit, making statutory damages exposure a board-level issue even when per-person recovery is modest. Individual class members in major TCPA settlements typically receive only $50–$300 per claim. The gap between the per-violation statutory figure and the per-claimant settlement amount reflects risk, certification posture, and claims rates, rather than a reduction in the theoretical exposure a defendant faces before settlement. Class action settlements averaged $6.6M in 2023, reflecting the gap between theoretical exposure and actual recovery.3
What Insurance Covers TCPA Claims?
Because statutory damages are uncapped and aggregate across a class, many businesses look to insurance as a backstop. That backstop is narrower than most assume.
Standard commercial general liability (CGL) policies often exclude TCPA claims under a violation-of-statutes exclusion. TCPA coverage typically lives in a media liability policy, a technology errors and omissions (E&O) policy, or a standalone endorsement. Businesses should confirm coverage in writing with their broker before a claim occurs.
The TCPA, CAN-SPAM, and similar statutory exclusion was incorporated as Exclusion p. of the standard CGL form in the 2007 ISO standard form revision and now appears on virtually every package policy, meaning GL Coverage B will not defend a TCPA text-message suit. Businesses that assume their CGL policy covers TCPA defense costs typically discover the exclusion only after they are served.
Three policy types are most commonly used to address TCPA exposure:
- Media liability policies (sometimes called Advertising Injury or Communications Liability): the most common home for TCPA coverage in a specialty policy, but some forms exclude claims arising from violation of any statute, which affects TCPA protection entirely.
- Technology E&O policies: some carriers have issued endorsements adding TCPA to their Tech E&O forms, with premium for a small team running roughly $3,000 to $7,000 per year at $1 million limits.
- Standalone TCPA endorsements: the clearest on coverage scope because there is no fight over whether “advertising injury” includes a text message, but limits tend to be lower at $500,000 to $2 million.
Key questions to raise with your broker before a claim occurs:
- Does the policy’s coverage grant explicitly name TCPA and telemarketing claims, or does a violation-of-statutes exclusion remove them?
- Are defense costs paid inside or outside the policy limit? Defense costs eroding the policy limit can drain a $1M E&O policy on legal fees alone.
- Does the intentional acts exclusion apply to knowing violations of a statute, or only to fraud and criminal acts?
- What is the retroactive date, and does it cover calls placed before the policy inception?
- Does the policy address state mini-TCPA claims, such as Florida’s FTSA (Florida Telephone Solicitation Act), in addition to federal TCPA claims?
This is a coverage landscape description, not legal or insurance advice. Confirm the specific terms of any policy with your broker and qualified counsel before relying on it for TCPA exposure.
Practical Ways To Reduce TCPA Exposure
The operational conditions that generate TCPA penalties on both tracks, private statutory damages and FCC civil forfeiture, share a common set of root causes. These include calls placed to numbers without valid consent, calls placed to DNC-listed numbers, calls placed outside permitted hours, and consent records that cannot be produced in litigation. Because each of those conditions occurs before the call connects, each can be addressed at the platform level before dial.

The core operational controls that reduce exposure on both tracks are:
- Consent-record hygiene: Timestamped, immutable records tied to the exact number dialed, retained long enough to produce in litigation. The strongest defense to ATDS or prerecorded-call claims is prior express written consent meeting the FCC’s 2012 consent rule, a signed written agreement, paper or electronic, with clear disclosure, but the consent record must be timestamped, tied to the exact number dialed, and retained long enough to produce in litigation.
- Revocation handling: Opt-out requests honored promptly across every channel, with suppression applied before the next outbound contact.
- DNC scrubbing: Telemarketers must scrub calling lists against the National Do Not Call Registry no more than 31 days before making any call, as described in the FCC’s implementing rules at 47 C.F.R. 64.1200(c).
- Quiet-hours enforcement: Automated application of federal and state calling-window restrictions by time zone on every outbound contact.
Plura AI is the platform built for high-volume operators who need these controls enforced at the carrier level before dial. Plura is an FCC-licensed platform of AI agents running voice, SMS, RCS, and AI webchat on 100% U.S. infrastructure. The Compliance Engine supports compliance with TCPA, DNC, HIPAA, SOC 2, CAN-SPAM, and 50+ state rule sets inside the platform on every outbound contact.1 Capabilities include real-time DNC scrubbing against federal and state registries before dial, timestamped and immutable consent records, automated quiet-hours enforcement through time-zone detection, and one-click audit-ready exports.

Plura’s AI Predictive Dialer and AI SMS channels run on the same Compliance Engine, so every outbound contact, whether a voice call or a text, passes through the same DNC scrubbing and consent-logging layer before it leaves the platform. The platform’s integrations with CRM systems keep consent records and suppression lists synchronized across the stack.

Plura supports customer compliance and does not make customers compliant. Customers remain responsible for their own regulatory obligations, consent practices, and the claims they make to their own end users.
Conclusion: Using The Two-Track Exposure Model
The two-track model above explains why TCPA exposure is difficult to cap. Private statutory damages aggregate across a class, FCC civil forfeiture operates independently, and DNC-registry penalties add a third set of figures. The operational conditions that generate exposure on all three tracks are addressable at the platform level.
Plura supports compliance by enforcing DNC scrubbing, quiet-hours rules, and consent logging inside the platform on every outbound contact. Plura supports customer compliance and does not make customers compliant. Customers remain responsible for their own regulatory obligations.
Compare plans and rates side by side.4
Run your numbers through Plura’s ROI calculator to check your cost savings in real time.
1 Plura AI maintains SOC 2, HIPAA, ISO, and GDPR posture as part of its platform infrastructure. References to compliance frameworks in this article describe Plura’s platform capabilities and do not constitute a guarantee that any customer using Plura will themselves be compliant with applicable laws or standards. Customers remain solely responsible for their own regulatory obligations, certifications, consent management, recordkeeping, and the claims they make to their own end users. Consult qualified legal counsel for guidance specific to your use case.
2 This article describes regulatory frameworks at a general level and does not constitute legal advice. Laws and regulations vary by jurisdiction, change over time, and apply differently depending on facts and circumstances. Readers should consult qualified legal counsel before making compliance decisions.
3 Performance figures, customer outcomes, and industry statistics referenced in this article are drawn from cited third-party sources or Plura customer case studies. Individual results vary based on implementation, use case, industry, audience, and execution. Past or aggregate performance is not a guarantee of future results.
4 References to third-party products, services, companies, or research are made for informational and comparative purposes only. Plura AI is not affiliated with, endorsed by, or sponsored by any third party named in this article unless explicitly stated. Trademarks and product names referenced remain the property of their respective owners.
This article is provided for informational purposes only and reflects Plura AI’s understanding at the time of publication. Product capabilities, integrations, and specifications are subject to change. For the most current information, visit plura.ai.
This article was produced with the assistance of AI tools and reviewed by Plura AI prior to publication.