TCPA compliance for calls and texts
The Telephone Consumer Protection Act (TCPA) is the federal law that governs how businesses may call and text consumers. Passed in 1991 and enforced through FCC rules and an aggressive private right of action, it is the reason "who am I actually dialing?" is a compliance question, not just a data-quality question. Statutory damages are $500 per call or text and up to $1,500 for willful violations, with no cap — which is why TCPA class actions routinely settle in the tens of millions.
This page explains the obligations in plain language. It is general information, not legal advice; outreach programs should be reviewed by counsel.
What does the TCPA require?
The core rules that trip up legitimate businesses:
- Consent for automated calls and texts to mobile numbers. Calls or texts to a cell phone using an autodialer or a prerecorded/artificial voice require the called party's prior express consent. Telemarketing calls need the stricter *prior express written consent*; purely informational calls (delivery notices, service alerts) need ordinary consent.
- Do-Not-Call compliance. Telemarketing calls may not go to numbers on the National Do Not Call Registry unless an exception applies (existing business relationship, written permission). Companies must also maintain an internal do-not-call list and honor it.
- Calling-time windows. Telemarketing calls are restricted to 8 a.m. to 9 p.m. in the *called party's* local time — another reason knowing the true location of the person behind a number matters.
- Honoring revocation. Consumers can revoke consent by any reasonable means, and recent FCC rules require honoring a revocation within ten business days. "Reply STOP" must actually stop.
- Identification. Callers must identify themselves and provide a contact number or address.
Debt collectors face additional conduct rules under the FDCPA, and several states layer their own "mini-TCPA" statutes (Florida and Oklahoma are the best known) with different consent definitions and windows.
Why do wrong-party calls create TCPA liability?
Consent attaches to a *person*, not to a phone number. Roughly 35 million U.S. phone numbers are disconnected and reassigned each year. When a number you have consent for is reassigned to a stranger, your next autodialed call is a call to someone who never consented — a textbook TCPA violation, even though your records say otherwise.
This is the single most common way careful organizations end up as TCPA defendants: the data went stale, not the process.
What is the Reassigned Numbers Database?
The FCC's Reassigned Numbers Database (RND) lets callers check whether a phone number has been permanently disconnected — and therefore possibly reassigned — since a date when they knew the number belonged to their intended recipient. Callers who check the RND and get a "no" answer earn a safe harbor from liability if the database turns out to be wrong.
The RND tells you a number *changed hands*; it does not tell you who holds it now. Pairing an RND check with a current consumer-records lookup — does this number still belong to the person I intend to reach? — is how outreach teams close that gap.
How does data quality reduce TCPA risk?
Three practices, all data-side, cut most wrong-party risk:
- Verify number ownership before campaigns. Search the number against current consumer records and confirm it still matches your intended contact's name before dialing. A reverse phone search that returns the current holder's name and a confidence signal makes this a batch job, not a manual one.
- Refresh stale contact records. If an account has not been contacted in months, treat its phone as unverified. Re-tracing the person and comparing the number on file against their current records catches reassignments the RND check alone would miss.
- Use the called party's real location. Area codes no longer imply location. Current address data gives you the called party's actual time zone for the 8 a.m.–9 p.m. window.
Does using a data provider make me TCPA compliant?
No — and be wary of any provider that says otherwise. Consent management, dialing technology, and call practices are the caller's responsibility. What a records provider like CoverFi contributes is the factual layer: whose number is this now, where do they live, and how confident is the match. CoverFi searches 250M+ people by phone, name, address, or email, labels exactly how each result matched, and prices per lookup with prepaid credits, so verifying a calling list costs a known amount per record. The same checks run programmatically through the REST API for teams that scrub lists at volume.