FCC TCPA Opt-Out Rules 2026: What the September 30 Vote Means for Your Business

FCC TCPA opt-out rules 2026
Editorial Transparency
Created by: Phone Service Now Editorial Team
Technical Review: Adam Nager, CEO of Phone Service Now

What Are the FCC’s New TCPA Opt-Out Rules?

As of September 2026, the FCC has scheduled a vote on September 30 to adopt a Report and Order that modernizes how consumers opt out of robocalls and robotexts under the Telephone Consumer Protection Act. The rulemaking would streamline consent revocation by requiring callers to provide a working, verifiable callback number and by potentially allowing businesses to designate specific opt-out methods rather than honoring revocation through any reasonable means, a shift from the current framework that has been delayed twice since 2025.

Revoke-all rule status: The provision requiring a single opt-out to cover all future communications from a caller is currently delayed until January 31, 2027. The September 30 vote may finalize or further modify this provision.

Callback number update: Current rules require callers to provide a number “other than a 900 number.” The proposal would replace this with a requirement for a working, verifiable number that accepts opt-out requests.

Who is affected: Every business that makes outbound calls or sends texts using a phone system, including VoIP and cloud-based platforms, falls under these TCPA provisions.

What the September 30 Vote Covers

The FCC announced on September 9, 2026, that the September Open Commission Meeting on September 30 will include a vote on a Report and Order and Further Notice of Proposed Rulemaking titled “Enhancing the Ability of Consumers to Control Which Calls That They Wish to Receive” (CG Docket No. 02-278). This is not a proposal. A Report and Order is a final rule. If the Commission adopts it on September 30, the changes become enforceable after publication in the Federal Register.

The rulemaking addresses two core areas. First, it modernizes how consumers revoke consent to receive robocalls and robotexts. Second, it updates caller identification requirements to reflect how phone technology actually works in 2026, including VoIP and cloud phone systems that did not exist when the TCPA was enacted in 1991.

The companion Further Notice signals that additional changes are under consideration beyond what the September 30 vote finalizes. This means businesses should treat the Report and Order as the beginning of a longer regulatory cycle, not a one-time adjustment. For businesses that rely on a VoIP phone system for outbound calling and texting, this vote directly shapes the compliance infrastructure you need to have in place by early 2027.

Who Needs to Comply With the New Revocation Rules?

Any person or business that makes calls or sends texts using an automatic telephone dialing system or an artificial or prerecorded voice is subject to the TCPA’s consent and revocation requirements. In practice, this covers most businesses that use a phone system for outbound communication, including appointment reminders, marketing calls, follow-up texts, and automated notifications.

The scope extends beyond traditional call centers. A medical practice that sends appointment reminder texts, an electrical contractor that calls customers about scheduled service, and a small business owner who texts promotional offers from a local number all fall under TCPA rules. The FCC’s analysis in related robocall proceedings has noted that covered entities could include VoIP resellers, cloud communications providers, PBX providers, and any service that furnishes or enables voice communications using North American Numbering Plan resources.

In our experience helping businesses set up their phone systems, the companies most likely to be caught off guard by TCPA changes are those in the 5- to 25-user range. They have enough outbound call volume to generate compliance risk but often lack a dedicated compliance team to track regulatory shifts. If your business falls in that range and you use texting or automated calling through your business phone system, this vote is directly relevant to your operations.

Why the FCC Is Modernizing TCPA Now

The current TCPA opt-out framework was built for a world of landline phones and paper do-not-call lists. Chairman Brendan Carr’s FCC has been on a sustained push to streamline and modernize regulatory requirements across all areas of the Commission’s jurisdiction, and TCPA rules are a priority target.

Several factors converged to put this on the September 30 agenda. The “revoke-all” provision, originally set to take effect April 11, 2025, has been delayed twice: first to April 11, 2026, and then to January 31, 2027. Each delay was granted because businesses, particularly financial institutions and multi-unit companies, argued they needed more time to modify communications systems to process a single opt-out as a blanket revocation across all business units. The FCC’s own Further Notice from late 2025 asked whether companies should be allowed to designate specific opt-out methods rather than being required to honor any reasonable means of revocation.

At the same time, the callback number requirement has become outdated. The existing rule mandates that automated callers provide a number “other than a 900 number,” language that dates to a time when premium-rate phone lines were the primary consumer protection concern. The proposed modernization would require a working, verifiable number that identifies the caller and accepts opt-out requests, aligning the rule with how consumers actually use caller ID in 2026.

How Will the Revoke-All Rule Change Affect Business Calls?

The revoke-all rule is the provision with the most operational impact for small and mid-sized businesses. Under the current framework that is set to take effect January 31, 2027, if a consumer sends a STOP reply to one type of message from your business, that revocation applies to all future calls and texts from your company, regardless of subject matter or business unit.

The September 30 vote may modify this. The FCC has asked whether businesses should be allowed to designate specific methods for opt-outs, such as requiring STOP via text or an opt-out link, rather than honoring any reasonable method. It has also asked whether certain opt-out methods should be required across the board and what safeguards are needed to prevent companies from making the opt-out process unreasonably complicated.

Here is how the revocation landscape has shifted and where it stands as of September 2026:

ElementBefore 2024Current Rule (Delayed)Proposed Change
Revocation scopeOpt-out applied to the specific type of communicationOne opt-out revokes consent for all calls and texts from that callerUnder review. May allow designated opt-out methods
Opt-out methodsNo specific method requiredAny reasonable method (STOP, verbal, email, etc.)Businesses may designate specific methods with required disclosures
Processing timeNo federal standard10 business days10 business days (unchanged)
Callback numberMust provide a number other than a 900 numberSame as beforeWorking, verifiable number that identifies the caller and accepts opt-out requests
Effective dateN/AJanuary 31, 2027 (twice delayed)To be determined by the September 30 vote

The practical consequence for a business running a VoIP phone system is that the compliance requirements around opt-out handling are about to become more specific. Whether the final rule loosens or tightens the current framework, it will require documented processes. We see this come up regularly when businesses onboard a new phone system. The ones that have call recording, message logging, and a structured opt-out workflow built in from day one handle regulatory shifts without scrambling. The ones that bolted texting onto an older system without thinking about compliance spend weeks patching gaps.

Phone Service Now includes call recording, texting with message logs, and voicemail documentation on every plan. If your current phone system does not give you the tools to handle opt-out requests and maintain consent records, now is the time to fix that before the new rules take effect.

What Your Business Should Do Before January 2027

Regardless of what the September 30 vote finalizes, the direction is clear: the FCC is tightening the framework around how businesses handle consent revocation. These steps prepare your business for the rules that are coming.

  1. Audit every outbound communication channel. List every way your business contacts customers: calls, texts, automated reminders, marketing campaigns. Identify which ones use an autodialer or prerecorded voice, because those are the ones the TCPA covers.
  2. Establish a single opt-out processing workflow. Whether the final rule requires you to honor any reasonable method or allows you to designate specific methods, your team needs one clear process for receiving, logging, and acting on opt-out requests within 10 business days.
  3. Verify your callback number works and identifies your business. The proposed rule would require a working, verifiable number that accepts opt-out requests. If your outbound calls display a number that goes to a dead line or a generic voicemail, fix it now.
  4. Enable call recording and text message logging. Compliance disputes come down to documentation. A phone system that records calls and logs texts with timestamps gives you a defensible record if a customer claims you ignored their opt-out request.
  5. Train your team on opt-out handling. Every person who makes calls or sends texts on behalf of your business needs to know what to do when a customer says stop. Verbal opt-outs during a call, STOP replies to texts, and email requests should all route to the same documented workflow.
  6. Review your phone system’s compliance features. If your current system does not log consent, timestamp opt-outs, or record calls, you have a gap. Plans from providers like Phone Service Now start at $18.99 a month per user and include texting, call recording, and voicemail-to-email transcription that supports compliance documentation.

Common Mistakes With TCPA Consent Revocation

The most common mistake we see businesses make is treating the TCPA deadline delays as a reason to wait. The revoke-all provision has been pushed back twice, and some business owners interpret that as a signal that enforcement is unlikely. It is not. The delays happened because businesses asked for more time to build compliance systems. The FCC granted that time. When the deadline arrives, the expectation is that you used it.

The second mistake is running opt-out handling through informal channels. A customer tells a sales rep on the phone that they do not want to be called again, and the rep makes a mental note. That mental note has no legal weight. Without a timestamped record in your phone system, you have no proof the opt-out was processed. TCPA penalties run $500 to $1,500 per violation, and each call or text after a revocation is a separate violation.

The third mistake is ignoring the cross-channel implications of the revoke-all rule. If a customer opts out of marketing texts, the current rule means they have also opted out of promotional calls, automated reminders, and any other communication that requires consent. Businesses with separate systems for calls and texts that do not share an opt-out database are the ones most exposed. A VoIP phone number that handles both calls and texts through the same platform simplifies this because the opt-out record lives in one place.

Frequently Asked Questions

When does the FCC vote on the new TCPA opt-out rules?

The FCC has scheduled the vote for the September Open Commission Meeting on September 30, 2026. If adopted, the Report and Order becomes a final rule and takes effect after publication in the Federal Register. The exact effective date will be stated in the published order.

What is the TCPA revoke-all rule?

The revoke-all rule requires that if a consumer revokes consent to one type of communication, such as a marketing text, that revocation applies to all future robocalls and robotexts from that business. It was adopted in February 2024 and has been delayed twice, with the current effective date set for January 31, 2027.

Do TCPA opt-out rules apply to VoIP phone systems?

Yes. The TCPA applies to any call or text made using an automatic telephone dialing system or prerecorded voice, regardless of whether the call originates from a traditional phone line, a VoIP system, or a cloud-based platform. VoIP providers and their business customers both have compliance obligations.

How fast does a business have to process an opt-out request?

Under the current rules, businesses must honor a consent revocation within 10 business days. The September 30 vote is not expected to change this timeline. Any call or text sent after the 10-day window following a valid opt-out request is a separate TCPA violation.

What are the penalties for violating TCPA opt-out rules?

TCPA penalties range from $500 per violation for standard infractions to $1,500 per violation for willful or knowing violations. Each individual call or text counts as a separate violation, so a single campaign sent after a revocation can generate substantial liability through class action litigation.

Will the new rules let businesses choose how customers opt out?

The FCC has asked for input on whether businesses should be allowed to designate specific opt-out methods, such as texting STOP or using an opt-out link, rather than accepting any reasonable method. The September 30 vote will determine whether this change is adopted and what disclosure requirements would apply.

Next Steps

Review your outbound call and text workflows and confirm your phone system logs consent and opt-out events with timestamps.

For more on how the FCC is reshaping robocall enforcement, see our coverage of the FCC robocall mitigation database overhaul.

If your current phone system does not support call recording, message logging, or documented opt-out workflows, those gaps need to close before January 2027.

Phone Service Now gives your business call recording, text message logging, and voicemail-to-email documentation on every plan, starting at $18.99 a month per user. Month-to-month service, no contracts, and setup in one business day. Get the compliance infrastructure you need before the TCPA rules change.