TCPA Compliance Guide for Calls, Texts and AI Outreach



May 8, 2025



TCPA compliance means following federal rules governing certain marketing calls, automated calls, prerecorded or artificial voice messages, and text messages.

For businesses, compliance involves more than adding an opt-out line to a message. You need to determine which rules apply, obtain the required consent, respect Do Not Call requests, control when communications are sent and retain evidence of permission.

These requirements are especially important for automotive dealerships that regularly contact internet leads, service customers and past buyers. A properly configured automotive CRM system can help dealerships organise customer records, communication histories and follow-up activities.

Important: This guide provides general information and is not legal advice. TCPA requirements can vary based on your communication method, campaign purpose and location. Consult qualified legal counsel before launching or changing a calling or texting campaign.

What Is the TCPA?

The Telephone Consumer Protection Act, or TCPA, is a US federal law that restricts certain telephone calls, text messages and fax communications.

The TCPA and related Federal Communications Commission rules address practices such as:

  • Calling or texting consumers without the required consent
  • Using artificial or prerecorded voices
  • Sending certain automated marketing communications
  • Contacting numbers on Do Not Call lists
  • Ignoring consent revocation or opt-out requests
  • Failing to identify the business responsible for a call

Text messages are generally treated as calls for TCPA purposes. The exact requirements depend on the technology used, the recipient, the purpose of the message and whether an exemption applies.

Who Must Comply with the TCPA?

TCPA compliance can affect any organisation that calls or texts US consumers, including:

  • Automotive dealerships
  • Financial services providers
  • Healthcare organisations
  • Real estate businesses
  • Retailers
  • Lead-generation companies
  • Marketing agencies
  • Call centres
  • Software providers acting on behalf of clients

A business may still face risk when communications are sent by an agency, technology platform or lead vendor on its behalf. Vendor contracts should therefore define compliance responsibilities, consent requirements, data ownership and audit rights.

What Communications Does the TCPA Cover?

The TCPA can apply differently to manual calls, automated calls, texts and prerecorded messages.

Marketing calls and texts

Communications encouraging a consumer to buy a product or service are generally subject to stricter requirements than purely informational messages.

Certain telemarketing calls or texts made using regulated technology may require the consumer’s prior express written consent.

Businesses should combine legal review with established SMS marketing best practices, including clear opt-in language, useful message content and accessible opt-out methods.

Informational communications

Appointment confirmations, service updates and other non-promotional messages may be treated differently from marketing communications. However, an informational message can become promotional when it includes an offer, discount or sales language.

Businesses should classify each campaign by purpose rather than assuming that every message sent to an existing customer is exempt.

Artificial, prerecorded and AI-generated voices

The Federal Communications Commission has confirmed that restrictions applying to artificial or prerecorded voices can include technologies that generate or simulate human voices.

Calls using these technologies generally require prior express consent unless an emergency purpose or exemption applies. Telemarketing calls using an artificial or prerecorded voice generally require prior express written consent.

An AI sales assistant should not be treated as an ordinary live agent simply because the generated voice sounds human.

TCPA Consent Requirements

Consent is one of the most important parts of TCPA compliance. The required level of consent depends on the campaign purpose and technology.

Prior express consent

Prior express consent may apply to some non-marketing communications. It can arise when a consumer knowingly provides a phone number for a purpose reasonably connected to the communication.

Providing a phone number does not automatically authorise every future marketing campaign.

Prior express written consent

Certain telemarketing communications require a signed written agreement that clearly authorises an identified seller to deliver marketing calls or texts using the specified technology.

The disclosure should be clear and conspicuous. It should also explain that consent is not a condition of purchasing goods or services.

Electronic actions such as checking an unchecked box, submitting a properly designed form or signing digitally may provide evidence of agreement, depending on the process and applicable law.

What consent records should include

A defensible consent record may include:

  • Consumer name and phone number
  • Date and time of consent
  • Form URL and page version
  • Exact disclosure displayed
  • Consumer action used to agree
  • IP address or technical record
  • Business or seller named in the disclosure
  • Permitted communication channels
  • Lead source
  • Consent withdrawal history

Do not rely only on a CRM label stating “opted in.” Retain evidence showing what the consumer saw and how they agreed.

A modern AI-native automotive CRM can help centralise lead details, communication histories, consent information and customer preferences.

Do Not Call Compliance

Businesses making telephone solicitations should maintain procedures for checking the National Do Not Call Registry and their own company-specific suppression list.

A practical Do Not Call programme should include:

  • A written compliance policy
  • Regular National Do Not Call checks
  • An internal Do Not Call list
  • Employee and contractor training
  • Controls preventing suppressed numbers from being re-added
  • Records showing when lists were checked
  • Oversight of agencies and call-centre vendors

An existing customer relationship should not be treated as unlimited permission to ignore an individual request to stop calling.

Opt-Out and Consent Revocation Requirements

Consumers must be able to revoke consent through reasonable methods. The FCC consent revocation rules explain how consumers may withdraw consent for covered robocalls and robotexts and how businesses should process those requests.

Depending on the channel, revocation may include:

  • Replying STOP to a text
  • Asking a representative not to call again
  • Submitting an online request
  • Contacting customer support
  • Using another clear method to request that communications stop

Your systems should distribute suppression requests across every relevant platform, including:

  • CRM records
  • Calling systems
  • SMS platforms
  • Marketing automation tools
  • Third-party agencies
  • Lead-management software

A consumer should not continue receiving messages because one system failed to synchronise with another.

The complete automotive CRM guide explains how centralised systems can help dealerships manage customer records, follow-up activity and communication workflows.

Calling Times and Identification

Federal telemarketing rules generally restrict outbound telemarketing calls to between 8:00 a.m. and 9:00 p.m. in the recipient’s local time, unless prior consent supports a different approach.

Businesses should also identify themselves accurately and provide truthful caller information. Avoid using misleading caller ID details or numbers consumers cannot use to contact the business.

State laws may impose narrower calling windows or additional requirements.

Reassigned Phone Numbers

Phone numbers can be transferred from one consumer to another. A valid consent record from the previous owner may not establish permission to contact the new owner.

Businesses can reduce reassigned-number risk by:

  • Checking eligible numbers against reassignment data
  • Monitoring long periods of inactivity
  • Investigating unexpected responses
  • Removing uncertain or invalid records
  • Reconfirming permission when appropriate

Recording database checks

TCPA Compliance for Automotive Dealerships

Dealerships communicate with consumers throughout the sales and ownership journey. Each campaign should be reviewed separately.

For a closer look at consent, recordkeeping and dealership messaging workflows, read our guide to automotive CRM texting compliance.

Internet and social media leads

Before calling or texting a lead, verify:

  • Where the lead originated
  • Which dealership was named
  • What disclosure the consumer saw
  • Whether the form covered calls, texts or both
  • Whether automated or artificial-voice communication was disclosed
  • When and how the consumer agreed

A purchased lead is not automatically a compliant lead.

Service and appointment messages

Appointment confirmations and service updates may have a different purpose from promotional campaigns. Keep transactional messages focused on the requested service.

Adding an unrelated trade-in offer or sales promotion may change the compliance analysis.

Equity-mining and sales campaigns

Messages encouraging customers to sell, trade or replace their vehicles are generally promotional. Review the consent record, technology, Do Not Call status and campaign timing before contact begins.

AI sales assistants

AI tools can support fast lead response, qualification and follow-up, but they should operate within documented controls.

When configured appropriately, AI texting for car dealerships can help teams respond to enquiries, answer common questions and schedule appointments.

Before using AI-generated voice or automated messaging, confirm:

  • The required consent has been recorded
  • The campaign matches the consent disclosure
  • The business is properly identified
  • Opt-outs are detected and synchronised
  • Calling-hour controls use the consumer’s local time
  • Conversations and system actions are auditable

Technology can support compliance, but it cannot guarantee that every campaign is legally compliant.

Common TCPA Compliance Mistakes

Frequent weaknesses include:

  • Using vague or pre-checked consent boxes
  • Failing to save the original disclosure
  • Treating every CRM lead as opted in
  • Mixing transactional and promotional content
  • Ignoring verbal Do Not Call requests
  • Contacting reassigned numbers
  • Sending messages outside permitted hours
  • Allowing vendors to use data for unrelated campaigns
  • Failing to synchronise suppression lists
  • Assuming carrier registration proves legal compliance

Registration for messaging programmes, including 10DLC, may support carrier requirements but does not replace TCPA consent or Do Not Call obligations.

TCPA Penalties

The TCPA permits eligible claimants to seek actual monetary loss or statutory damages of up to $500 for each violation. Courts may increase damages for knowing or wilful violations.

Because campaigns may involve many calls or texts, repeated violations can create substantial financial exposure. Businesses may also face regulatory action, legal costs and reputational damage.

TCPA Compliance Checklist

Before launching a campaign:

  1. Define whether the message is informational or promotional.
  2. Document the calling or messaging technology used.
  3. Confirm the required form of consent.
  4. Retain the complete consent record.
  5. Check national and internal Do Not Call lists.
  6. Review reassigned-number risk.
  7. Apply the recipient’s local calling window.
  8. Identify the business accurately.
  9. Provide reasonable opt-out methods.
  10. Synchronise suppression requests across every system.
  11. Train employees and vendors.
  12. Audit campaigns and records regularly.
  13. Review applicable state laws.
  14. Obtain legal advice for higher-risk campaigns.

How TCPA Compliance Software Can Help

Compliance software can help businesses manage:

  • Consent records
  • Do Not Call checks
  • Opt-out processing
  • Communication histories
  • User permissions
  • Campaign schedules
  • Audit logs
  • CRM integrations
  • Suppression lists
  • Vendor activity

Modern dealership texting software may also help centralise conversations, automate routine replies and preserve communication histories.

These tools reduce manual work and support consistent processes. However, software must be configured correctly and used alongside appropriate policies, training, vendor management and legal review.

How SimpSocial Supports Compliance Workflows

SimpSocial helps automotive businesses manage leads and customer communication through connected sales and marketing workflows.

Depending on the selected features and configuration, the platform may help teams centralise contact records, retain communication histories, manage campaign permissions and respond to customer preferences.

Businesses remain responsible for determining which laws apply, collecting valid consent, reviewing campaign content and configuring their systems appropriately.

Build Compliance into Every Customer Conversation

TCPA compliance should be part of campaign design, not a final check performed after a call or text programme has been created.

Responsible outreach can also strengthen automotive customer engagement by making communications relevant, timely and respectful of each customer’s preferences.

By collecting verifiable consent, respecting opt-out requests, maintaining accurate suppression lists and reviewing automated communications carefully, businesses can reduce risk while building greater trust with customers.

FAQ's

Does the TCPA apply to text messages?

Yes. Text messages are generally treated as calls for TCPA purposes. The applicable consent requirements depend on the message purpose and technology.

A verbal request may be a reasonable method of revocation. Staff should record it immediately and ensure it reaches every relevant communication system.

A STOP reply is a recognised method for opting out of covered text messages. Businesses should also monitor other reasonable language showing that a recipient wants messages to end.

AI-generated or simulated human voices may fall within restrictions applying to artificial or prerecorded voices.

The appropriate retention period depends on applicable limitation periods, regulations and business risk. Ask legal counsel to establish a documented retention policy.

No. Software can support consent, suppression and audit processes, but compliance also depends on campaign design, data quality, employee conduct, vendor activity and legal requirements.

Picture of SimpSocial
SimpSocial

SimpSocial empowers modern dealerships with two game-changing solutions: precision-targeted social media lead generation tied to live inventory, and a powerhouse ai automotive crm engagement platform that responds, follows up, and books appointments automatically.

Learn More






No leads were lost. reduced overhead.
Swipe to setup a demo
Swipe to learn more