Summary. The TCPA is thirty-five years old, was written about fax machines and robocalls, and is now the most expensive statute in American marketing because it pays $500 per message with no cap. A single campaign to fifty thousand numbers creates $25 million of nominal exposure before anyone asks whether the messages were annoying. This article explains what the statute prohibits after the Supreme Court narrowed the autodialer definition in Facebook v. Duguid, why prerecorded voice calls and the do-not-call rules remain the live exposure, what consent must look like and how to document it, how revocation works after the FCC's recent rulemaking, and where state statutes go further. It closes with a compliance program that actually prevents claims.


Every general counsel who has handled one of these matters describes the same moment. Marketing ran a campaign. It performed well. Six weeks later a demand letter arrives from a firm that has filed two hundred of these, attaching a single text message and proposing a class of everyone who received the campaign.

The arithmetic is what makes the conversation difficult. Statutory damages are $500 per violation, trebled to $1,500 for a knowing or willful violation, with no cap and no requirement of actual damages. A list of 50,000 recipients is $25 million of exposure, or $75 million if willfulness is found. No plaintiff needs to prove they were harmed, annoyed, or even that they read the message.

That structure — uncapped per-message statutory damages plus a class device — is why the TCPA generates more class filings than almost any other consumer statute, and why the compliance question is not "is this a good practice" but "can we prove consent for every single number on that list, today, in a form a court will accept."

What the statute prohibits

47 U.S.C. § 227 contains several distinct prohibitions. Practitioners collapse them and then misjudge the risk.

1. Calls using an automatic telephone dialing system (ATDS) or an artificial or prerecorded voice to a cellular telephone, without the prior express consent of the called party. § 227(b)(1)(A)(iii).

2. Prerecorded voice calls to residential landlines for telemarketing purposes, without prior express written consent. § 227(b)(1)(B).

3. Telemarketing calls to numbers on the National Do Not Call Registry, and calls to persons who have asked to be placed on the caller's internal do-not-call list. Implemented by 47 C.F.R. § 64.1200(c) and (d).

4. Unsolicited advertisements sent by facsimile, under the Junk Fax Prevention Act.

Text messages are "calls." The FCC concluded this early and courts have uniformly agreed. Every rule above applies to SMS and MMS.

Facebook v. Duguid, and what it did and did not change

Facebook, Inc. v. Duguid, 592 U.S. 395 (2021), resolved a deep circuit split over the definition of an ATDS: equipment with the capacity "to store or produce telephone numbers to be called, using a random or sequential number generator," and to dial them.

The holding. The qualifying phrase modifies both "store" and "produce." To be an autodialer, a device must use a random or sequential number generator either to store or to produce the numbers it dials. A system that dials from a stored list of specific customer numbers — which is what essentially every modern marketing platform does — is not an ATDS.

What that eliminated. The § 227(b) autodialer theory, which had been the engine of TCPA litigation for a decade. A company texting its own customer list from a modern platform is not using an ATDS, and the ATDS prohibition does not apply.

What it left completely intact, and where the exposure now lives:

  • Prerecorded and artificial voice calls to cell phones. The statute prohibits these independently of the ATDS question, and it always has. This is now the single largest source of § 227(b) liability.
  • The do-not-call rules in § 227(c) and 47 C.F.R. § 64.1200(c)–(d), which have never required an autodialer. Any telemarketing call or text to a registry number, or to someone who asked not to be contacted, is actionable regardless of the technology.
  • The internal do-not-call list requirements, including the obligation to maintain written policies, train personnel, and honor requests for five years.
  • State statutes, several of which define autodialer more broadly than the federal statute as construed.
  • AI-generated voices. The FCC has confirmed that voices generated by artificial intelligence are "artificial" voices within the statute — a conclusion with obvious significance for AI calling agents.

The practical reframing: post-Duguid, a text-message compliance program is really a consent and do-not-call program, not a technology program. The question is no longer what system you used. It is whether you had permission and whether the person had asked you to stop.

Consent: two different standards

Prior express consent — for non-telemarketing calls and texts to a cell phone. Informational messages: appointment reminders, delivery notifications, fraud alerts, account servicing. The FCC has long taken the position that a consumer who provides their number to a business in connection with a transaction has given prior express consent to receive informational calls at that number regarding that transaction. Consent need not be written.

Prior express written consent — required for telemarketing or advertising calls and texts to a cell phone, and for prerecorded telemarketing to a residence. 47 C.F.R. § 64.1200(f) defines it as a written agreement, signed by the consumer, that:

  • clearly authorizes the seller to deliver advertisements or telemarketing messages using an ATDS or prerecorded voice;
  • includes the telephone number to which the signer authorizes messages;
  • clearly and conspicuously discloses that the messages may be delivered using an ATDS or prerecorded voice, and that consent is not a condition of purchase; and
  • is signed in a manner satisfying ESIGN, which an electronic signature does.

Note the "not a condition of purchase" requirement. A checkout flow that will not proceed unless the box is checked violates the rule even if everything else about the disclosure is perfect.

What a defensible consent record contains — because the burden of proving consent is on the caller, and this is where cases are actually won and lost:

  • The exact disclosure text displayed at the moment of consent, retained by version and date range.
  • A screenshot or rendering of the page or form as the consumer saw it.
  • The timestamp, IP address, and session identifier.
  • The phone number as entered.
  • The method: web form, text keyword opt-in, paper form, verbal with recording.
  • For keyword opt-ins, the inbound message and the confirmation message sent.
  • Retention for at least the four-year federal limitations period plus a margin, and longer where a state statute is longer.

Purchased lists are not consent. Neither is a list acquired in an asset purchase, absent evidence the consent covered the acquirer. Neither is a consent given to an affiliate, unless the disclosure named the affiliate or a defined and disclosed group.

Lead generation is the highest-risk area. A consumer who enters a number on a comparison website that discloses sharing with "marketing partners" and links to a list of six hundred companies has not, on most courts' analysis, given the specific consent the rule requires. The FCC adopted a rule requiring one-to-one consent — consent to a single, identified seller, with the messages logically and topically related to the interaction — but the Eleventh Circuit vacated that rule in Insurance Marketing Coalition Ltd. v. FCC, 127 F.4th 1179 (11th Cir. 2025), holding that the Commission exceeded its authority by adding requirements beyond the statutory term "prior express consent." The vacatur restored the prior status quo, but it did not make broad-consent lead generation safe: courts continue to evaluate whether the disclosure gave consent to this seller, and buyers of leads bear the burden of proving it.

Practical guidance for lead buyers regardless of the rule's status: require the vendor to deliver, per lead, the disclosure text, the URL, a rendering of the page, and the full metadata; audit a sample independently rather than accepting a certification; and negotiate an indemnity that is worth something, backed by insurance, recognizing that most lead vendors cannot fund a class judgment.

Revocation

A consumer may revoke consent, and how easily has been contested for years. The FCC's 2024 revocation order settled much of it:

  • Revocation may be made by any reasonable means. A consumer is not required to use a specific word, a specific channel, or the mechanism the sender designated.
  • Replying "stop," "quit," "end," "revoke," "opt out," "cancel," or "unsubscribe" to a text message is per se reasonable, and a sender may not designate an exclusive method that excludes these.
  • Revocation in response to one type of message from a sender is treated as revoking consent for all robocalls and robotexts from that sender, unless the consumer indicates otherwise — a significant change for companies that maintained separate marketing and servicing consent.
  • Requests must be honored within a reasonable time not to exceed ten business days.
  • A single confirmation message acknowledging the opt-out is permitted, if sent within five minutes and containing no marketing content.

The contractual consent question. Reyes v. Lincoln Automotive Financial Services, 861 F.3d 51 (2d Cir. 2017), held that consent given as a bargained-for term of a contract — a lease agreement in which the consumer agreed to be contacted at a given number — cannot be unilaterally revoked, applying ordinary contract principles. Other circuits have permitted revocation of consent that was merely given, not bargained for. The distinction is real but narrow, and relying on it is risky: the FCC's revocation order takes a broad view, the doctrine has limited acceptance, and the reputational cost of continuing to text someone who said stop exceeds any operational benefit. Honor every opt-out.

The do-not-call rules

These survived Duguid untouched and are now the most common theory in new filings.

The National Do Not Call Registry. Telemarketing calls and texts to a registered residential or wireless number are prohibited unless:

  • the caller has the consumer's signed, written agreement identifying the number and authorizing calls; or
  • an established business relationship exists — a purchase or transaction within 18 months, or an inquiry or application within three months — and the consumer has not asked to be placed on the caller's internal list.

Internal do-not-call requirements47 C.F.R. § 64.1200(d). A person or entity making telemarketing calls must:

  • maintain a written policy, available on demand;
  • train personnel engaged in telemarketing on the existence and use of the list;
  • record and honor a do-not-call request within a reasonable time not exceeding 30 days, and honor it for five years;
  • identify the caller, the entity on whose behalf the call is made, and a telephone number or address for that entity;
  • access the National Registry no more than 31 days before the call and maintain records documenting the process.

Courts have divided on whether § 64.1200(d)'s internal-list requirements are privately enforceable under § 227(c), with several circuits holding they are. Assume they are.

Timing. Telemarketing calls and texts are prohibited before 8:00 a.m. or after 9:00 p.m. in the called party's local time. Determining local time from an area code is unreliable given number portability, and this is a frequent, entirely avoidable violation.

Standing, and where these cases are litigated

TransUnion LLC v. Ramirez, 594 U.S. 413 (2021), requires a concrete injury for Article III standing, and a statutory violation alone does not supply one. The question for TCPA cases is whether receiving unwanted messages is concrete.

The Eleventh Circuit held in Salcedo v. Hanna that a single text was not enough, then overruled that holding en banc in Drazen v. Pinto, 74 F.4th 1336 (11th Cir. 2023), concluding that unwanted texts bear a close relationship to the traditional harm of intrusion upon seclusion and therefore confer standing. Other circuits had reached the same result for calls and texts.

The practical consequence is a strange one: standing doctrine now cuts primarily against defendants, because a defendant that removes a case to federal court and then wins on standing gets a remand, not a dismissal — and state courts, several of which do not apply Article III standing requirements, may be a worse forum. Removal decisions in TCPA cases should account for that.

Class certification turns on whether consent can be resolved on common evidence. A defendant with consistent, well-documented consent records paradoxically faces a higher certification risk, because the records are common evidence; a defendant with chaotic records may defeat certification on predominance grounds while facing terrible individual exposure and a court that assumes the worst. Neither is a strategy. The strategy is to have consent for everyone.

Vicarious liability

A seller may be liable for calls made by a third party under federal common law agency principles — actual authority, apparent authority, or ratification — a position the FCC articulated in its 2013 DISH Network declaratory ruling and that courts have applied since.

Facts that establish apparent authority or ratification: giving the vendor access to customer information or systems, allowing use of the seller's brand or trademarks, approving scripts, setting call parameters, accepting and processing leads generated by conduct the seller knew about, and continuing the relationship after complaints.

Contract terms do not by themselves defeat vicarious liability. A vendor agreement stating that the vendor is an independent contractor and will comply with the TCPA is necessary but not sufficient. What helps: genuine independence, no control over dialing, documented diligence, contractual audit rights actually exercised, prompt termination on complaints, and an indemnity backed by insurance and a solvent counterparty.

State statutes, which now drive much of the risk

Federal law is a floor. Several states have enacted mini-TCPAs that are broader, and litigation has migrated toward them.

  • Florida Telephone Solicitation Act. Amended in 2021 to create a private right of action with $500 statutory damages for calls or texts made using an "automated system for the selection or dialing of telephone numbers" — a definition far broader than the federal ATDS. A 2023 amendment narrowed the private right of action, adding a requirement that the recipient reply "STOP" and that the sender fail to honor it within 15 days, and imposing a prior express written consent requirement for the covered conduct. Both the original and amended versions have generated substantial litigation.
  • Oklahoma enacted a similar statute in 2022.
  • Washington's Commercial Electronic Mail Act and its telephone solicitation statutes reach commercial text messages, with damages and Consumer Protection Act remedies.
  • Maryland, Michigan, New York, and others impose registration requirements, bonding, curfews narrower than the federal window, or restrictions on specific practices.
  • State do-not-call registries persist in a number of states with independent obligations.

The compliance instruction: determine every state where recipients are located — which is every state, for a national program — and comply with the strictest applicable rule on consent, curfew, disclosure, and revocation. Building a program to the federal minimum and hoping is not a plan.

Carrier and industry rules

Independent of law, the wireless carriers impose requirements that will shut down a non-compliant program faster than any lawsuit.

  • 10DLC registration. Application-to-person messaging over standard ten-digit long codes requires registration of the brand and each campaign, with the use case, sample messages, and opt-in mechanism disclosed. Unregistered traffic is filtered or blocked.
  • CTIA Messaging Principles and Best Practices, which carriers enforce contractually: clear opt-in, confirmation messages that identify the program and disclose message frequency and data rates, "reply STOP to opt out" and "HELP for help" language, and prohibitions on certain content categories.
  • Content restrictions. Cannabis, firearms, certain lending products, and gambling face categorical blocking on many carriers regardless of state legality.
  • Consequences. Campaign suspension, number blocking, brand-level penalties, and aggregator termination — commercially severe and immediate.

Building a program that prevents claims

Consent capture.

  • Use a separate, unchecked consent checkbox for marketing messages. Never bundle it with terms of service acceptance.
  • Display the complete disclosure adjacent to the checkbox, not behind a link: who is sending, what kind of messages, approximate frequency, that automated technology may be used, that message and data rates apply, that consent is not a condition of purchase, and how to opt out.
  • Capture the number in the consent record, not merely in the account profile.
  • For keyword opt-ins, retain the inbound message and send an immediate confirmation stating the program name, frequency, rates, and opt-out instructions.
  • Version every disclosure and retain each version with its effective dates. When a plaintiff who signed up in 2023 sues in 2026, you must produce the 2023 text.

Suppression.

  • Maintain a single, authoritative internal do-not-call list that every system consults before every send. The most common technical failure is a second platform — an email tool with SMS features, a CRM, a franchisee's own system — that does not see the list.
  • Scrub against the National Registry within 31 days for any telemarketing send, and retain the scrub records.
  • Scrub against state registries where applicable.
  • Honor opt-outs across all programs and brands by default.
  • Suppress reassigned numbers using the FCC's Reassigned Numbers Database, which provides a safe harbor for calls to a number reassigned after consent was given, if the database was queried and returned no reassignment.
  • Enforce curfews by the recipient's actual time zone, using a carrier lookup rather than area code inference.

Governance.

  • A written policy meeting § 64.1200(d), reviewed annually.
  • Training for marketing, sales, and any customer-facing team that collects phone numbers.
  • Pre-approval of every campaign by someone accountable, with a checklist covering list source, consent basis, disclosure version, curfew, and content.
  • Vendor management: diligence before engagement, contractual compliance obligations and audit rights, actual audits, indemnity plus insurance, and immediate escalation on complaints.
  • Complaint tracking. A pattern of complaints that the company failed to act on is the evidence that turns $500 into $1,500 per message.
  • Insurance. Most CGL policies exclude TCPA claims, often through the "distribution of material in violation of statutes" exclusion. Confirm coverage explicitly and consider a specific TCPA endorsement or a media liability policy that addresses it. Discovering the exclusion after the demand letter is a recurring and expensive surprise.

Records. Retain consent records, disclosure versions, suppression lists, scrub logs, campaign approvals, and vendor audits for at least five years — the internal do-not-call retention period, which exceeds the four-year limitations period.

Responding to a demand or a filed case

  1. Preserve immediately. Litigation hold covering the marketing platform, CRM, consent database, vendor communications, and complaint records. Vendor data is the most likely to disappear, and vendor contracts should already require preservation on notice.
  2. Pull the individual plaintiff's record first. Consent, disclosure version, opt-out history, and the actual messages. A significant fraction of these cases involve a plaintiff who did consent and never opted out, or who opted out and then re-subscribed, and the record ends it quickly.
  3. Assess the class. How many numbers, from what sources, with what consent documentation. This determines everything about strategy, and the honest number is often worse than marketing believes.
  4. Evaluate the professional-plaintiff angle. A meaningful number of TCPA plaintiffs maintain multiple lines for the purpose of generating claims. Discovery into the plaintiff's phone usage, prior suits, and how the number was provided is legitimate and frequently productive — though courts limit fishing.
  5. Check arbitration. If the plaintiff has an account governed by terms containing an arbitration clause with a class waiver, that is usually the fastest path out. Confirm the clause covers the claim and that assent is provable.
  6. Evaluate coverage and notice carriers on every potentially applicable policy immediately.
  7. Fix the practice. Continuing the conduct after notice is the fact that produces willfulness findings and punitive settlement demands.

A concluding perspective

The TCPA is an awkward statute. It was enacted in 1991 to address a technology that has essentially disappeared, its central definition was so contested that it took thirty years and a Supreme Court decision to settle, and its damages provision produces exposure wildly disproportionate to the harm any individual suffers. Defense counsel are right that a great deal of TCPA litigation is manufactured, and that the class device converts a minor annoyance into a nine-figure demand.

All of that is true, and none of it helps a company that ran a campaign it cannot document consent for. The statute is what it is, the plaintiffs' bar is organized and well-financed, and the practical question is never whether the exposure is fair.

The good news is that compliance is genuinely achievable, and it is not expensive. A separate checkbox, a complete disclosure, a retained record with a timestamp, one suppression list every system respects, honored opt-outs, and a curfew check. That is the entire program. Companies that do those six things almost never face a TCPA class action, and the ones that do face one resolve it by producing a record.

The companies that get sued are the ones where marketing bought a list, or a franchisee used its own platform, or the opt-out list lived in a spreadsheet. Those are not legal failures. They are operational ones, and they are fixed by someone owning the process rather than by anyone reading the statute.

Enforcement beyond private suits

Private class actions dominate the headlines, but three other enforcement channels matter.

The FCC. The Commission issues forfeiture orders, and the amounts have been extraordinary — hundreds of millions of dollars against robocall operations, spoofing schemes, and lead generators. Its authority over spoofing comes from the Truth in Caller ID Act, 47 U.S.C. § 227(e), which prohibits transmitting misleading or inaccurate caller ID information with intent to defraud, cause harm, or wrongfully obtain anything of value. The Commission has also required voice service providers to implement STIR/SHAKEN caller ID authentication, to file robocall mitigation plans in a public database, and to block traffic from providers that have not — which means a marketing operation with poor practices can find its calls blocked at the network level rather than merely litigated later.

State attorneys general. The TCPA authorizes state AGs to bring civil actions on behalf of residents, and a multistate task force has coordinated investigations of gateway providers carrying illegal traffic. State consumer protection statutes supply parallel authority with their own penalties.

The FTC. The Telemarketing Sales Rule, 16 C.F.R. Part 310, overlaps substantially with the TCPA and adds requirements the TCPA does not contain: prompt disclosure of the caller's identity and the purpose of the call, prohibitions on misrepresentation, restrictions on advance fees for certain services, express verifiable authorization for particular payment methods, and a call abandonment standard limiting dead air. Violations carry civil penalties per violation that are adjusted annually and are substantial. Companies frequently build a TCPA program and overlook the TSR, which reaches conduct the TCPA does not.

The overlap matters for scoping. A compliance review that examines only § 227 will miss the TSR's disclosure and abandonment rules, the FCC's caller ID authentication obligations, and the state registration and bonding requirements that apply to telephone solicitors in roughly half the states. Build the checklist from all of them at once.

Special contexts

Debt collection and account servicing. Calls to collect a debt are not telemarketing, so the do-not-call rules generally do not apply, and prior express consent — satisfied by providing the number in connection with the account — usually covers them. But the FDCPA imposes its own restrictions on time, place, and frequency, Regulation F caps call frequency with a presumption of harassment above defined thresholds, and revocation still applies to prerecorded messages. A servicer's TCPA program and its FDCPA program should be designed together.

Healthcare. The FCC has exempted certain healthcare messages from the written-consent requirement where they have a healthcare treatment purpose, are free to the recipient, and satisfy content and frequency limits. Appointment reminders, prescription notifications, and pre-operative instructions generally qualify. Marketing, accounting, billing, and payment messages do not, and the boundary between a wellness reminder and a marketing message is where the disputes occur.

Political and nonprofit calls. Tax-exempt nonprofit organizations are exempt from the national registry rules and from certain prerecorded-message restrictions, but not from the cell phone prohibitions in § 227(b) when using a prerecorded voice. Political calls are similarly exempt from the registry but subject to identification requirements and to the § 227(b) rules.

Employers and recruiting. Text-based recruiting to candidates whose numbers came from a resume database is a genuine gray area: it is not obviously telemarketing, but it is also not the informational messaging that consent-by-providing-the-number was meant to cover. Treat recruiting outreach as requiring express consent, obtained through an opt-in on the application or job board rather than assumed from the presence of a number on a resume.

A worked compliance review

Here is what an actual review of a mid-sized retailer's texting program finds, and it is representative.

Finding 1 — Three sources of numbers, one consent record. Numbers enter from the e-commerce checkout, from in-store point-of-sale where associates ask for a mobile number to email a receipt, and from a sweepstakes entry form. Only the checkout captures a marketing consent. The point-of-sale numbers were loaded into the marketing platform because "the customer gave us the number." That is consent for a receipt, not for advertising, and roughly a third of the list has no lawful basis for telemarketing messages.

Finding 2 — The disclosure is behind a link. The checkbox says "I agree to receive offers by text. See terms." The required disclosures — automated technology, message frequency, rates, and that consent is not a condition of purchase — live two clicks away. Fixable in an afternoon, and until it is fixed every consent captured is contestable.

Finding 3 — Two platforms, one suppression list. Marketing sends from a modern platform that honors STOP automatically. The loyalty program sends from a separate tool configured three years ago by a vendor, and its opt-out list was never merged. People who opted out of marketing continue to receive loyalty messages, and the FCC's cross-program revocation rule makes each one a violation.

Finding 4 — No disclosure versioning. The consent language has changed four times. Nobody kept the prior versions, and there is no way to prove what a customer who signed up in 2022 actually saw.

Finding 5 — Curfew set by area code. A customer with a New York area code living in Los Angeles receives messages at 5:15 a.m. local time. Number portability makes area code a poor proxy, and carrier lookup services that return the actual rate center or a time zone are inexpensive.

Finding 6 — A franchise channel nobody knew about. Twenty-two franchised locations run their own local texting through a small vendor, using lists built from paper sign-up sheets. The brand's name is on every message. That is apparent authority, and the franchisor is exposed for conduct it does not control and cannot document.

Remediation, in priority order: merge suppression lists across every sending system today; suspend telemarketing sends to the point-of-sale and sweepstakes segments until consent is re-obtained; fix the checkout disclosure and begin versioning; deploy time-zone lookup; and bring the franchise channel onto the corporate platform under a written policy with audit rights. None of that requires litigation counsel. All of it requires someone with authority to tell marketing to stop sending to a third of the list, which is the part that does not happen without a general counsel making it happen.

One structural recommendation. Assign ownership of the calling and texting program to a single named person with authority over every sending system in the company, including the ones marketing bought without telling anyone. Every failure catalogued above is a coordination failure rather than a legal one, and coordination failures persist until someone is accountable for them by name.

Primary authority

The TCPA is a short statute with an enormous regulatory and judicial superstructure.

  • 47 U.S.C. § 227 — the statute, including the automatic telephone dialing system and artificial-or-prerecorded-voice prohibitions in § 227(b), the do-not-call provisions in § 227(c), and the private right of action with statutory damages of $500, trebled for willful or knowing violations.
  • 47 C.F.R. § 64.1200 — the implementing rules, including the written consent definition in § 64.1200(f)(9), the internal do-not-call list requirements, and the revocation rules.
  • Facebook, Inc. v. Duguid, 592 U.S. 395 (2021) — narrows the autodialer definition to equipment using a random or sequential number generator, which moved most litigation to prerecorded-voice and do-not-call theories.
  • Barr v. American Association of Political Consultants, Inc., 591 U.S. 610 (2020) — severs the government-debt exception on First Amendment grounds while leaving the rest of the statute intact.
  • PDR Network, LLC v. Carlton & Harris Chiropractic, Inc., 588 U.S. 1 (2019) — the Hobbs Act question about deference to FCC orders in private litigation.
  • Campbell-Ewald Co. v. Gomez, 577 U.S. 153 (2016) — an unaccepted offer of judgment does not moot a class representative's claim.
  • Spokeo, Inc. v. Robins, 578 U.S. 330 (2016) and TransUnion LLC v. Ramirez, 594 U.S. 413 (2021) — concrete injury, and the standing arguments that now shape class certification.
  • 15 U.S.C. §§ 7701–7713 (CAN-SPAM) and 16 C.F.R. Part 316 — the email analogue, with no private right of action.
  • Fla. Stat. § 501.059, Okla. Stat. tit. 15 § 775C.1, and comparable state mini-TCPA statutes — the newer, sometimes broader, state layer.

Related articles

This article is provided for general informational purposes and does not constitute legal advice. FCC rules in this area change frequently and several are subject to pending litigation, and state statutes impose additional and sometimes stricter requirements. Consult qualified counsel before launching a calling or texting program or responding to a demand.