TCPA

TCPA Compliance Software: What It Does and What It Cannot Do

TCPA violations run $500 to $1,500 per call or text, and the rules tightened again in 2025 and 2026. Compliance software helps, and a small agency should probably use some form of it. But vendors oversell what a tool can cover. Here is what the software actually does, where it stops, and why a one page written policy still matters more.

THE STAKES

What TCPA Compliance Means in 2026

The Telephone Consumer Protection Act is the 1991 federal law that governs automated calls and texts. What makes it dangerous for a small agency is the private right of action: any consumer can sue for $500 per violating call or text, and up to $1,500 when the violation is willful or knowing. Every message is a separate violation, which is how routine follow up campaigns turn into class actions. The rules also moved recently, so advice from even two years ago may be stale.

Revocation rule, April 2025

Since April 11, 2025, consumers can revoke consent by any reasonable means, including replies like STOP, QUIT, END, REVOKE, OPT OUT, CANCEL, or UNSUBSCRIBE, and you must honor it within 10 business days. The old 30 day cushion is gone.

Broader scope, April 2026

One piece of that rule is still on hold: the requirement that a revocation cover all your future robocalls and robotexts to that person, not just the campaign they replied to, has been pushed back by the FCC to January 31, 2027 (order DA 26-12, released January 6, 2026), while the agency considers changing it. The rest of the revocation rule has been in effect since April 2025. The safe practice does not change: treat one STOP as stop for everything.

One to one rule vacated

A federal appeals court struck down the FCC's one to one consent rule in January 2025, days before it took effect. Bundled lead consent survived in court, but consent still has to be real, documented, and provable to be worth anything.

WHAT IT DOES

The Four Jobs of TCPA Compliance Software

Strip away the marketing and most tools in this category do four things. All four are genuinely useful, because they are exactly the tasks humans forget under pressure.

1. Consent capture

Records who agreed, when, from what IP address, on which form, and the exact disclosure text they saw. That record is what stands between you and a he-said-she-said dispute. The wording itself still has to be right, and we cover that in our TCPA opt in language guide.

2. Quiet hours enforcement

Federal telemarketing rules bar solicitation calls before 8 am and after 9 pm in the recipient's local time, and several states are stricter. Good software holds messages until the window opens. Ask how it determines local time, because area code is a guess, not a location.

3. DNC scrubbing

Checks numbers against the National Do Not Call Registry and your internal suppression list before anything goes out. FTC rules require registry data no more than 31 days old. For fiscal year 2026 the FTC's access fees are $82 per area code, with the first five free and a national cap of $22,626.

4. Audit trails

An exportable log of every consent, every send, every opt out, and when each opt out was honored. If a demand letter ever arrives, this log is the first thing your attorney asks for, and the tools earn their fee right there.

WHAT IT CANNOT DO

What the Software Will Not Do for You

The gaps matter more than the features, because the gaps are where agencies get sued anyway.

Create consent you never collected

Software documents consent. It cannot conjure it. If you buy leads, the consent question lives with the lead seller's forms, and a scrubbing tool cannot make a bad lead source safe.

Fix your opt in language

The tool stores whatever disclosure your form showed. If that wording is missing an element, every record it faithfully keeps is a record of invalid consent.

Decide the gray areas

Is a renewal reminder informational or marketing? Can you text a former client? Software has a setting for each answer, but a human has to choose it, ideally with an attorney's input.

Control your staff's phones

A producer texting prospects from a personal cell bypasses every control you bought. No platform can log a message it never touched.

Write your policies

Tools enforce rules. They do not decide who may text, from which numbers, with what consent, or who reviews the logs. Those are policy decisions, and they belong on paper.

Defend you by itself

A vendor's compliance badge is not indemnification. Read the contract: nearly every tool in this category disclaims legal responsibility for your messaging. The records help your defense. They are not the defense.

EVALUATION

How a Small Agency Should Evaluate Tools

You do not need an enterprise compliance suite. You need the four jobs above, done reliably, at a price that makes sense for a 1 to 25 person shop. If your CRM or texting platform already does them well, a separate tool may be redundant. Ask these questions either way.

QuestionWhat a Good Answer Sounds Like
Where do consent records live, and can I export them anytime?One click export, no fee, in a readable format. Consent proof you cannot retrieve does not exist.
When someone replies STOP, what exactly happens, and how fast?Immediate automatic suppression across texts and automated calls, logged with a timestamp, well inside the 10 business day requirement.
Does it scrub against the national registry and my internal list automatically?Yes, on every send, with registry data refreshed inside the 31 day window, not a manual monthly chore someone has to remember.
How does it determine a contact's local time for quiet hours?An honest answer. Most tools use area code and should say so, plus how they handle mismatches and stricter state windows.
What happens to my records if I cancel?A full export and a stated retention period. Litigation can arrive years after the message was sent.
POLICIES FIRST

Where Written Policies Matter More Than Software

Here is the part vendors skip. The FTC's do not call safe harbor, the main defense when an accidental call slips through, is built on written procedures: documented practices, trained staff, monitoring, a properly accessed registry subscription, and proof the violation was an honest error. Software is evidence inside that defense. The written policy is the defense. A one page document that names who may call and text, from which numbers, what consent is required first, how opt outs are handled and by when, and who reviews the log each month will do more for a small agency than any feature on a pricing page. Write it, have your attorney review it, train everyone once a year, and let the software enforce it. This article is general information, not legal advice, and the penalties involved are exactly why the attorney hour is worth it.

Compliance Gaps Are Usually Revenue Leaks Too

The same audit that finds where your agency loses money to missed calls, slow lead response, and unworked renewals also surfaces where consent and follow up records are a mess. Our AI Revenue Leak Audit gives you a written report and a prioritized fix list. $1,500, currently $750 at the introductory rate.

More from the blog