Every political text a campaign sends is governed by the Telephone Consumer Protection Act, and political campaigns are not exempt from it. What campaigns get is a narrower standard than commercial marketers, not a free pass. This guide covers the whole thing: what the TCPA requires, what political speech is and isn't exempt from, how consent, opt-outs, sender identification, and quiet hours work in practice, how the one-to-one consent rule rose and fell, why state laws are now the real complexity, and what it costs to get it wrong. It's long because a thin answer to this question is how campaigns end up in court.
Does the TCPA apply to political campaigns?
Yes. The most expensive myth in political texting is that the First Amendment exempts campaigns from the TCPA. It doesn't. Political speech gets more room than a retailer's coupon, but the statute still applies to texts sent to cell phones.
The Supreme Court settled the frame in 2020. In Barr v. American Association of Political Consultants, the Court struck down a narrow government-debt carve-out but left the TCPA's restrictions on automated calls and texts intact. The takeaway for operators is simple. Being a campaign changes which consent standard applies to you. It does not remove the obligation to have consent, to stop when someone says stop, to say who you are, and to text at a decent hour.
What consent do political campaigns actually need?
Campaigns need consent, just not the prior express written consent that binds commercial marketers. That's the whole distinction, and it's worth being precise about, because "we're a campaign, we don't need consent" is both common and wrong.
Commercial marketing that uses an autodialer requires prior express written consent, a signed, unambiguous agreement to receive marketing texts. Political messaging is generally held to a lower bar: express or implied consent, without the signed-form requirement. In practice, valid consent for a political program looks like a voter who did one of these:
- Opted in through a web form, a text-to-join keyword, or an event signup.
- Checked a box to receive campaign updates.
- Gave the campaign their number directly, at a door, a rally, or a booth.
What is not consent, no matter how often it's treated as if it were:
- A voter file. It gives you the number. It does not give you permission.
- A purchased or rented list. Buying numbers and texting them cold is the exact behavior the rules exist to stop, and the liability sits with you, the sender, not the vendor who sold the list.
- Consent given to a different organization. One committee's opt-in is not another's.
The safe operating rule: capture your own consent, at the source, and be able to point to the moment it happened.
The four obligations on every political text
Strip away the edge cases and every compliant political text meets four requirements, every time.
| Obligation | What it means in practice |
|---|---|
| Consent | Express or implied consent before the first message. No signed form required for political speech, but a real opt-in you can document. |
| Opt-out honored | A STOP reply stops messages automatically and permanently, processed in seconds, not by a staffer the next morning. |
| Sender identification | Every message names the campaign or committee clearly, so the recipient knows who is texting them. |
| Reasonable hours | Send within the recipient's local daytime window, commonly treated as 8 a.m. to 9 p.m., tighter where a state says so. |
Miss any one of these and the message is a problem, even if the other three are perfect.
How to handle opt-outs the right way
An opt-out has to be instant, automatic, and permanent. When a recipient replies STOP, END, QUIT, UNSUBSCRIBE, or CANCEL, the messages stop, and they stay stopped. The carriers enforce STOP at the network level for standard keywords, but your platform still has to record the opt-out against that number and never message it again, across every campaign that touches the same contact.
HELP is the companion requirement. A HELP reply returns a short message identifying the campaign and how to get assistance. Both STOP and HELP handling should be built in, not bolted on, because "we forgot to process an opt-out" is not a defense a plaintiff's lawyer will let pass.
The operational failure to watch for is the human-worded opt-out. A voter who replies "please take me off this list" hasn't typed a magic keyword, but they've asked to leave, and a program that only catches literal STOP will keep texting someone who clearly opted out. Good programs read intent, not just keywords, and hold the number the moment a person asks.
Sender identification and disclaimers
Every message has to make clear who's sending it. Name the committee or campaign in the text, and where a paid communication requires it, include the "paid for by" disclaimer your jurisdiction expects. This is both a TCPA-adjacent expectation and, for many campaigns, an election-law one. The practical version: a voter should never have to wonder who just texted them, and they should be able to tell a legitimate campaign from a spoof at a glance.
Quiet hours and reasonable times
You can't text a voter in the middle of the night. The long-standing federal benchmark for calls is 8 a.m. to 9 p.m. in the recipient's local time, and texting programs are expected to respect the same reasonable-hours principle. The words that trip campaigns up are recipient's local time. A campaign texting a multi-state list has to resolve the hour against each person's own state, not the sender's.
State law increasingly tightens this. Several states now set their own windows and caps, and a send that's fine at 8:15 p.m. in one state can be a violation in the next one over. The reliable approach is to let the platform queue and release per recipient, holding a message that would land in someone's quiet hours until their local window opens. For the full picture, see the state-by-state breakdown of quiet hours.
Record-keeping: the four-year rule
Keep your records for at least four years. That means the opt-in event, the messages you sent, and the opt-out, each attributable to a specific number with a timestamp. This is not bureaucratic hygiene. It's the entire defense. If a carrier audit or a TCPA complaint arrives, the question is always the same: can you show consent for this number, on this date, and can you show you honored the opt-out? A campaign that can produce that record is defensible. A campaign that can't is exposed, regardless of how careful it actually was.
The one-to-one consent rule, explained
You'll hear "one-to-one consent" invoked as if it's current law. As of 2026, it isn't, and the story matters because it shows where consent standards are heading.
In December 2023, the FCC issued a rule requiring one-to-one consent, meaning a single opt-in covering a batch of loosely related "marketing partners" would no longer be enough. Each business would have to obtain its own consent directly, aimed squarely at the lead-generation loophole. It was set to take effect in early 2025. Days before the deadline, the Eleventh Circuit vacated it in Insurance Marketing Coalition v. FCC, finding the agency had exceeded its authority, and the FCC subsequently eliminated the rule.
So one-to-one consent is not a federal requirement today. But the underlying standard it tried to codify, that consent belongs to the specific sender a person agreed to hear from, never went away, and carriers and states are tightening around the same idea independently. If your list was built on shared or purchased consent, that's a risk whether or not this specific rule is on the books.
State mini-TCPA laws are the new frontier
The federal floor is no longer the whole story. A wave of state "mini-TCPA" statutes now layers extra requirements on top, and they don't agree with each other. A few campaigns are watching closely:
- Florida tightened its windows and added a cap on messages per recipient per day, with a private right of action.
- Texas expanded the scope of its deceptive-practices law to cover SMS, adding a new avenue for claims.
- Virginia added consent and identification requirements for automated political outreach.
- Connecticut and Arizona carry their own consent, do-not-contact, and penalty regimes.
The specifics shift every cycle, and the details are the point: a program that's compliant federally can still violate a state statute in a district you're texting into. The operating rule is to know the states you actually send to and build to the strictest one on your map.
Peer-to-peer texting and the human-intervention question
Peer-to-peer texting sits in a different posture, and it's worth understanding why rather than treating it as a loophole. When a real person manually initiates each message, the send generally falls outside the TCPA's autodialer definition, which is what triggers the strict prior-express-written-consent standard. That's why campaigns use P2P for initial voter contact and persuasion, where a documented prior opt-in may not exist.
Two cautions. First, the human-intervention posture changes the consent question, not the rest. Carrier registration, sender identification, STOP handling, content rules, and state law all still apply to P2P. Second, "a human pressed send" has to be true. A tool that automates the sending and calls it P2P invites a plaintiff to argue you behaved like an automated system. Capture consent anyway, and document the human-in-the-loop workflow. For the strategic side of when to use each, see P2P vs broadcast.
TCPA and 10DLC are two obligations, not one
Campaigns conflate these constantly, and they're separate. The TCPA is the federal statute, enforced through the courts, that governs consent and how you may contact someone. 10DLC is the carrier registration, enforced at the network, that governs whether your messages get delivered at all. You can be perfectly TCPA-compliant and still have every message filtered because you never registered, and you can be registered and still get sued because you texted without consent. You need both. See what 10DLC means for your campaign for that side.
What it costs to get it wrong
The TCPA carries statutory damages of $500 to $1,500 per message, and because a campaign sends in volume, those numbers scale into class-action territory fast. The other cost is quieter and just as real: non-compliant traffic gets filtered by the carriers, so money spent on messages that never arrive is money burned, and you often can't even see the drop. Between the legal exposure and the deliverability hit, cutting compliance corners is the most expensive way to save time in political texting.
A pre-launch compliance checklist
Before a single message goes out:
- Confirm you have documented consent for every number, attributable to a specific opt-in event.
- Register your brand and campaign for 10DLC and, for 527 traffic, complete Campaign Verify.
- Set STOP and HELP to process automatically, and confirm human-worded opt-outs are caught.
- Put your committee name in every message, with the disclaimer your jurisdiction requires.
- Configure quiet hours per recipient local time, tightened to the strictest state you send into.
- Turn on record retention for opt-ins, sends, and opt-outs, and keep it for four years.
Common mistakes campaigns make
The recurring failures are predictable: texting a purchased list or a raw voter-file match and calling it consent; treating one committee's opt-in as another's; processing opt-outs by hand or a day late; ignoring state quiet-hour windows on a multi-state send; and keeping no durable record of any of it. Every one of these is avoidable, and every one is a live claim if a plaintiff goes looking.
Frequently asked questions
Do political texts need written consent?
No. Political campaigns are exempt from prior express written consent, the signed-form standard that binds commercial marketers. They still need some form of consent, must honor STOP immediately, must identify themselves in every message, and must text during reasonable hours.
Are political campaigns exempt from the TCPA?
No. Political speech has First Amendment protection, but Barr v. AAPC (2020) left the TCPA's restrictions on automated texts to cell phones intact. Campaigns are exempt only from the written-consent rule, not from the statute.
How long must a campaign keep consent records?
At least four years. Store the opt-in event, the messages sent, and the opt-out, each tied to a specific number and timestamp. That record is your defense if a complaint or audit arrives.
Does the TCPA cover peer-to-peer texting?
P2P with genuine human intervention generally falls outside the autodialer definition, so the strict written-consent test often doesn't control. Everything else, carrier registration, sender ID, STOP handling, and state law, still applies.
What are the penalties for a TCPA violation?
$500 to $1,500 per message in statutory damages, which scales into class-action exposure at campaign volumes.
Keep reading: what 10DLC means for your campaign and quiet hours by state. For the official source, see the FCC's rules on telemarketing and robocalls.
This is general information for campaign operators, not legal advice. The TCPA, FCC rules, and state statutes change, and this reflects the landscape as of the date above. Confirm specifics with counsel before you send.