Last updated: July 2026 · ~7 min read · Educational, not legal advice.
What the TCPA is — and why it targets contractors
The Telephone Consumer Protection Act (TCPA) governs how businesses can call and text consumers. It was written for telemarketers, but it applies to anyone sending automated messages — including the HVAC and plumbing shops that now run appointment reminders, "tech is on the way" texts, review requests, and AI phone answering. The law is enforced largely through private lawsuits, and a cottage industry of professional plaintiffs actively looks for automated messages sent without provable consent.
The TCPA doesn't care that you're a good operator. It cares whether you can prove the customer agreed — for every message you sent.
The four things you must be able to prove
Compliance isn't a feeling; it's evidence. For every number you contact, you should be able to produce:
- Consent — a record that the customer agreed to be texted or called, including when and to what wording.
- Do-Not-Call screening — proof you checked the number against the registry before contacting it.
- An audit trail — a complete, tamper-evident history of every message, searchable in seconds.
- Reasonable limits — sensible caps so a customer isn't hit with a barrage of automated texts.
What a TCPA violation costs
Statutory damages are $500 per message, rising to $1,500 per message for willful or knowing violations. Because it's per message, the math compounds fast: one automated blast to a few hundred non-consented numbers is a five- or six-figure exposure before you've paid a lawyer. A typical single claim runs about $50,000 to defend and settle — and then your E&O premium moves.
Consent, in practice
For marketing messages, the standard is prior express written consent. For purely transactional service messages a lower bar can apply — but you still must be able to show the customer agreed and honor every opt-out. The defensible approach that covers both: capture consent at intake (web form, voice script, or an SMS reply), record the exact wording and timestamp, sign it so it can't be altered, and verify it before every send. (See our step-by-step on where your current setup stands.)
Does AI or a chatbot change anything?
Automation doesn't lower your obligations — it raises the stakes, because it multiplies the number of messages you have to be able to defend. An AI receptionist that texts a booking confirmation is still sending a message that needs consent, a DNC check, and a record. Compliant-by-construction intake (consent and DNC enforced before anything sends) is the cleanest way to run automation safely.
How to make your intake provably compliant
You don't need to rip out your tools. The practical path is to harden what you already run:
- Scan & score your live SMS, call and web intake against a defined control set.
- Remediate the gaps — signed consent, an immutable audit trail, DNC screening, rate limits.
- Document it in a compliance binder you can hand an insurer or attorney.
- Monitor going forward, so a control that slips gets caught before it becomes a claim.
That's exactly what Grandeza does across a 16-control hardening engagement, and the free Grandeza Score tells you where you stand today in about 12 minutes.
This guide is educational and general in nature. Grandeza provides compliance engineering, not legal advice; consult your attorney for advice about your specific situation.
Dig deeper