What About TCPA Compliance for RCS?
TCPA requires prior express written consent for marketing messages sent via RCS. Recipients must opt-in via clear disclosure, you must honor opt-out requests within 10 days, maintain do-not-call lists, and document consent. Violations result in $500-$1,500 per message fines. SMS fallback messages are also subject to TCPA.
Key Points
- Prior express written consent required for marketing
- Honor opt-out requests within 10 days
- Maintain internal do-not-call lists
- Document consent with timestamp and method
- { "Violations": "$500-$1,500 per message" }
RCS and TCPA Compliance: US-Specific Requirements
TCPA (Telephone Consumer Protection Act) governs RCS messaging in the US. Compliance is critical.
TCPA Requirements for RCS
Prior Express Written Consent:
- Required for marketing messages
- Must be in writing (electronic signature OK)
- Must include clear disclosure that customer agrees to receive messages
- Must identify the business sending messages
- Must describe message frequency
Opt-Out Handling:
- Must honor STOP keyword requests within 10 days (best practice: 24 hours)
- Must process opt-outs across all campaigns and systems
- Must send confirmation of opt-out
- Cannot charge for opt-out
Do-Not-Call Lists:
- Must maintain internal suppression lists
- Must scrub against national DNC registry (for some message types)
- Must honor DNC requests for 5 years
Calling Time Restrictions:
- Cannot send marketing messages between 9 PM and 8 AM (recipient's local time)
- Some states have stricter rules
Acceptable Consent Methods
Web form:
- Clear disclosure: "I agree to receive marketing messages from Business via RCS at the phone number provided. Message frequency varies. Message and data rates may apply. Reply STOP to opt out."
- Unchecked checkbox (user must actively check)
- Submit button labeled appropriately
SMS keyword:
- Customer texts keyword to short code
- Receives confirmation with opt-out instructions
- Must reply to confirm (double opt-in)
Paper form:
- Signature with disclosure
- Clear identification of business
- Message frequency disclosure
In-store:
- Tablet or paper signup
- Same disclosure requirements
- Document with timestamp
Documentation Requirements
For each opt-in, document:
- Phone number
- Date and time of consent
- Method of consent (web, SMS, in-store, etc.)
- IP address (if web)
- Exact disclosure shown
- Consent record (screenshot, database record, signed form)
Retention: Minimum 4 years (some recommend 5+ years)
Opt-Out Processing
When someone opts out:
- Add to suppression list immediately
- Sync suppression list across all systems
- Send confirmation: "You've been unsubscribed. Reply HELP for help."
- Stop all marketing messages
- Document the opt-out (timestamp, method, phone number)
- Retain opt-out record for 5 years
Suppression list sync:
- Daily sync between RCS platform and CRM
- Real-time sync for opt-outs
- Weekly sync with email suppression
- Quarterly review and cleanup
Penalties for Non-Compliance
TCPA violations:
- $500 per unsolicited message
- $1,500 per message if willful violation
- Class action lawsuits common
- No cap on total damages
Real-world examples:
- Small business: $50K-$500K settlements
- Large enterprise: $10M-$100M+ settlements
- Class actions: Can exceed $1 billion
Best Practices
- Use double opt-in for highest compliance
- Include clear opt-out instructions in every message
- Honor opt-outs within 24 hours (not 10 days)
- Document everything
- Train team on TCPA requirements
- Audit consent records quarterly
- Work with legal counsel
Common TCPA Mistakes
- Accepting consent without proper disclosure
- Not honoring opt-outs promptly
- Missing suppression list sync
- Sending messages outside allowed hours
- Not documenting consent properly
The Bottom Line
TCPA compliance is mandatory for RCS in the US. Use proper consent mechanisms, honor opt-outs immediately, document everything, and maintain clean suppression lists.
The fines are real and substantial. Invest in compliance upfront to avoid millions in penalties later.
Related Questions
Compliance
What's the Brand Verification Process for RCS?
Complete brand verification with legal docs and assets so carriers approve your sender identity—for operators starting RCS setup right.
Compliance
Is RCS Compliant with Privacy & Data Protection Laws?
RCS can support GDPR and CCPA when consent, retention, and processors are controlled—for legal and marketing leaders before rollout.
Compliance
How Does RCS Handle GDPR Compliance?
Treat RCS under GDPR with lawful basis, DPAs, and data-minimization controls—for EU-focused privacy and marketing teams before launch.
Compliance
Is RCS Compliant with HIPAA for Healthcare Messaging?
HIPAA-ready RCS needs BAAs, PHI safeguards, and carefully vetted vendors—for healthcare operators planning patient messaging programs.
Still have questions?
Schedule a free consultation with our RCS specialists to discuss your specific needs.
Schedule Consultation
