Federal TCPA (47 U.S.C. § 227) regulates SMS and voice on US telephone infrastructure and does not attach to WhatsApp Business Platform messages, which travel over an internet data connection. However, three other frameworks continue to bind US small business WhatsApp messaging: Meta's own opt-in and template requirements enforced at the platform layer, FTC Section 5 deceptive-practices standards, and state mini-TCPA statutes including Florida's FTSA, California's CIPA (Penal Code § 632 and § 632.7), Oklahoma's OTSA, and Washington's Consumer Protection Act. The 2021 Supreme Court decision in Facebook v. Duguid narrowed federal ATDS scope but state jurisprudence has moved to fill parts of the gap. Federal statutory damages are $500 per message trebled to $1,500 for willful violations, with historical class-action settlements in the low- to mid-eight-figure range. Regulated verticals — healthcare (HIPAA), financial services (GLBA, Regulation Z), debt collection (FDCPA, Regulation F), children (COPPA) — face additional overlays that this framework does not fully cover.
How the US Telephone Consumer Protection Act applies to WhatsApp Business — and where SMS, voice, and state mini-TCPA statutes leave the compliance line.
The Telephone Consumer Protection Act (47 U.S.C. § 227) is the US federal statute passed in 1991 and repeatedly amended that regulates telemarketing calls, text messages sent using an automatic telephone dialing system (ATDS), prerecorded or artificial-voice messages, and unsolicited faxes placed to US telephone numbers. It is administered by the Federal Communications Commission (FCC) with concurrent enforcement authority in the Federal Trade Commission and private right of action available to individuals under a statutory-damages framework.
The TCPA's substantive rules turn on four questions applied in sequence: (1) does the communication use an ATDS or a prerecorded or artificial voice, (2) is the recipient number a US mobile telephone number or a landline, (3) is the message content marketing or informational, and (4) has the required consent been captured. The applicable consent standard varies with the answer to question three — prior express consent for informational messages to mobile numbers, prior express written consent for marketing messages to mobile numbers, and established business relationship exceptions that narrowed substantially after the FCC's 2012 rulemaking.
FCC interpretive guidance has evolved through a series of rulings that operators must track: the 2012 declaratory ruling that tightened the prior-express-written-consent standard, the 2015 TCPA Omnibus Order that expanded ATDS interpretation, the 2021 Supreme Court decision in Facebook v. Duguid that narrowed ATDS to systems using a random or sequential number generator, and subsequent FCC guidance in 2023 and 2024 responding to Duguid. The Duguid decision materially reduced federal TCPA exposure for many business text platforms that previously operated under litigation risk, but state-level statutes have moved to fill parts of the gap, and litigation continues under state mini-TCPAs.
Statutory damages under the TCPA sit at $500 per violating message or call and are trebled to $1,500 per violation for willful or knowing violations. Damages accrue per message, per recipient, and class-action litigation has produced multi-million-dollar settlements — publicly reported class settlements in the low- to mid-eight-figure range for platforms that operated with defective consent workflows at scale. Attorney fee-shifting is not available under federal TCPA, but is available under several state mini-TCPA statutes.
The TCPA regulates communications placed to a US telephone number using US telephone infrastructure — the Public Switched Telephone Network for voice, and the mobile carrier SMS/MMS network for text. WhatsApp Business API is over-the-top messaging over an internet data connection. A WhatsApp message is not a call placed to a telephone number in the § 227 statutory sense, and it is not an SMS or MMS text message routed through carrier infrastructure. Federal TCPA prior-express-consent and prior-express-written-consent requirements consequently do not attach to WhatsApp Business Platform messages in the way they attach to SMS marketing sent through Twilio A2P 10DLC, MessageBird, or a traditional SMS marketing platform.
That legal-scope answer is only the first step. Three separate frameworks continue to bind a US small business sending automated WhatsApp Business messages to customers:
Meta's own opt-in requirements. The WhatsApp Business Platform Terms of Service and Meta's Commerce and Business Messaging Policies require that a recipient opt in through a documented channel before receiving a business-initiated conversation. Meta enforces these requirements at the platform layer through account quality ratings, phone-number blocking, and template rejection. In some respects Meta's standard is stricter than TCPA — Meta requires prior opt-in documentation for all business-initiated conversations, not merely marketing content, and Meta bans bulk-marketing patterns that fall inside TCPA's transactional-message safe harbor.
FTC Section 5 deceptive-practices standards. Section 5 of the Federal Trade Commission Act (15 U.S.C. § 45) prohibits unfair or deceptive acts or practices in commerce and applies to any US consumer commercial communication regardless of channel. An automated WhatsApp message that misrepresents the sender's identity, misrepresents the reason for contact, or fails to honor a documented opt-out request creates FTC Section 5 exposure independent of TCPA.
State consumer-protection statutes. State-level analogs to the TCPA — the Florida Telephone Solicitation Act (FTSA), the California Invasion of Privacy Act (CIPA), the Oklahoma Telephone Solicitation Act (OTSA), and Washington's Consumer Protection Act — have been read broadly enough in some jurisdictions to reach automated business messaging that federal TCPA does not clearly cover. State law is discussed in the next section.
Several US states have enacted messaging-regulation statutes that reach further than the federal TCPA, particularly after the Supreme Court narrowed ATDS in Facebook v. Duguid (2021).
Florida Telephone Solicitation Act (FTSA) — Florida amended the FTSA in 2021 to establish a private right of action for consumers receiving telemarketing text messages and phone calls sent using automated systems, with statutory damages of $500 per violation trebled for willful violations. The 2023 amendments partially narrowed the private right but the statute continues to generate active class-action litigation against SMS marketing platforms. Business-initiated messaging to Florida mobile numbers should be reviewed against current FTSA scope regardless of channel.
California Invasion of Privacy Act (CIPA) — California Penal Code § 632 and § 632.7 govern the recording of confidential communications and cellular telephone calls respectively. CIPA has been read in some California cases to apply to certain forms of automated business messaging on the theory that the messaging platform's back-end infrastructure records or intercepts the communication. The doctrinal question is unsettled and litigation continues.
Oklahoma Telephone Solicitation Act (OTSA) — Oklahoma enacted a mini-TCPA in 2022 with statutory damages of $500 per violation and a private right of action. The statute has generated active litigation particularly against SMS marketing platforms serving Oklahoma consumers.
Washington Consumer Protection Act (RCW 80.36 and RCW 19.86) — Washington's Consumer Protection Act combined with the state's telephone-solicitation statute provides for treble damages and attorney fees for violations, with a lower per-message damage floor than federal TCPA but broader liability triggers in some fact patterns.
Operational conclusion for a US small business sending automated messages to consumers in multiple states: state-level compliance risk continues to attach to automated business messaging even when the federal TCPA channel-scope question resolves in the business's favor. Counsel review of the consent flow before deployment is the minimum defensible practice for any business messaging Florida, California, Oklahoma, or Washington residents at scale.
For a US small business selecting a customer-messaging channel stack, the compliance surface differs materially across three configurations.
Full SMS stack via A2P 10DLC. Modern US business SMS runs through the A2P 10DLC framework: a brand registration through The Campaign Registry (TCR), a campaign registration per use case, phone-number provisioning through a carrier or CPaaS vendor (Twilio, MessageBird, Sinch, Bandwidth), throughput tiering based on trust score, and mandatory STOP/HELP keyword handling. Prior express written consent must be captured with clear disclosure language for marketing content; prior express consent (a lower standard) covers informational content. The full stack requires documented opt-in flow with timestamp and consent language, DNC list scrubbing against the National Do Not Call Registry where applicable, and a paper trail sufficient to defend a class action. Per-message cost via Twilio A2P 10DLC sits at approximately $0.0079 per outbound US message plus registration and campaign-vetting fees.
Full WhatsApp Business Platform stack. WhatsApp Business API runs through a Meta Business Solution Provider (BSP) or Meta's own Cloud API, with Meta Business Manager verification, phone-number connection, template message pre-approval (Meta reviews template text before allowing outbound business-initiated conversations), and opt-in capture at the point of first contact. TCPA prior-express-consent workflow does not apply at the federal level, but Meta's own opt-in documentation and the state-level analog framework still bind. Per-conversation cost via Meta sits at approximately $0.008 to $0.014 per US utility conversation and higher for marketing conversations, with pricing that varies by country and conversation type.
Multi-channel stack. Most US small businesses running customer messaging at scale operate a multi-channel stack — SMS for the older-demographic and rural-market segment where WhatsApp coverage is thin, WhatsApp for the urban and immigrant-community segment where WhatsApp is already daily contact, and email for longer-form communication. Compliance obligations accumulate across each channel: TCPA and A2P 10DLC for the SMS surface, Meta opt-in and template approval for the WhatsApp surface, and CAN-SPAM Act (15 U.S.C. § 7701 et seq.) for the email surface. The operational discipline is to run consent capture and opt-out handling once at customer intake, with the elected channels documented per contact.
The economic decision is rarely dominated by per-message cost; it is dominated by (1) which channels the actual customer population uses daily, and (2) which compliance stack the business has the operational discipline to run without dropping the consent-documentation practice. A cheaper SMS stack that fails a TCPA class action is not cheaper.
This piece is a plain-language overview of the federal TCPA framework and its intersection with WhatsApp Business Platform messaging for a US small business. It is not legal advice, and it does not substitute for consultation with qualified US counsel about a specific business's regulatory posture. TCPA case law and FCC interpretive guidance continue to evolve; state mini-TCPA jurisprudence continues to develop; and the doctrinal boundary between federally-preempted and state-level messaging regulation remains actively litigated.
Businesses operating in regulated verticals face additional overlays that this article does not cover in depth:
Any US small business operating in one of these verticals, or handling large-volume outbound consumer messaging, should have counsel review the messaging compliance posture before deployment. The cost of legal review is materially less than the cost of a TCPA or state mini-TCPA class action.
Data + numbers referenced in this article are sourced from these public documents:
Not ready to sign up yet? Try the free demo →