ComplianceApril 8, 202611 min read

TCPA Compliance for HOAs: What Every Board Must Know Before Texting Residents

A practical TCPA primer for HOA boards. The four pillars of compliance, the consent records that hold up under legal review, and the mistakes that turn a $200 broadcast into a $15,000 lawsuit.

TT

TextHOA Team

Compliance & legal

Most HOA boards discover the Telephone Consumer Protection Act (TCPA) the wrong way: a resident threatens to sue, an attorney sends a demand letter, or the management company's SMS provider suddenly suspends the account "pending consent verification." None of these end well. The good news is that TCPA compliance for an HOA is conceptually simple: four rules, a recordkeeping practice, and a willingness to say "no" when someone wants to add a phone number you have not opted in.

This is not legal advice. It is an operational primer that boards can use to set up their messaging program correctly the first time, then cite when a resident or auditor asks how the system works.

What the TCPA actually says

The TCPA (47 U.S.C. § 227) is a 1991 federal statute amended several times, most consequentially by the Federal Communications Commission's 2012 ruling and the 2015 Omnibus Order. The relevant provisions for HOA messaging:

  • You must have prior express consent before sending any non-emergency text to a residential or wireless number.
  • "Prior express written consent" is required for any message that is "telemarketing", which the FCC has interpreted broadly. To be safe, treat all HOA messages as requiring written consent.
  • You must honor opt-out requests immediately. The CTIA Short Code Monitoring Handbook makes "STOP" universal.
  • Statutory damages are $500 per violation, trebled to $1,500 if the violation is "knowing or willful." There is no harm requirement; a single un-consented text is a complete cause of action.

Does the TCPA really apply to HOAs?

Yes. This is a frequent source of confusion because HOA messages are "informational" rather than "marketing." But the FCC's 2003 ruling and subsequent enforcement makes clear that the TCPA applies to any "automated or prerecorded" messages to a wireless number, regardless of content. Mass texting from a platform is automated. The only narrow exception is genuine emergencies, life-safety alerts where time is critical.

There is a partial defense for "informational" (non-telemarketing) messages: oral consent may suffice. But because boards rotate, paper records get lost, and oral consent is hard to prove three years later, the safe practice is to capture written consent for everything. The handful of extra clicks costs nothing; a TCPA defense costs $20,000+ in legal fees even if you win.

The four pillars of TCPA compliance for an HOA

Express written consent is a clear statement, signed (electronically or on paper) by the resident, that authorizes the HOA to send messages to a specific phone number. The consent statement must:

  • Identify the sender ("Maple Hills HOA") and what kinds of messages will be sent (announcements, reminders, emergency alerts)
  • State the phone number being authorized
  • Disclose that consent is not a condition of any service or membership
  • Include the standard opt-out language ("Reply STOP to unsubscribe; reply HELP for help")
  • Mention message and data rates may apply

2. Audit-grade recordkeeping

Every consent action must produce a record. Treat the consent log like the meeting minutes: append-only, never edited, retained for at least five years (the statute of limitations for TCPA claims is four years; one year of buffer is reasonable). For each record, capture:

  • Member ID and phone number
  • Action: granted, declined, revoked, reinstated
  • Method: paper form, portal opt-in, SMS keyword reply, email link
  • Timestamp (UTC, with original timezone preserved)
  • IP address (for portal opt-ins) or signature image (for paper)
  • Version of the consent language shown to the resident
  • Who recorded it (board member, automated system, the resident themselves)

Why all of this? Because in TCPA litigation, the defendant has the burden of proving consent. "We assumed they consented because the previous board did" is not a defense. A timestamped record showing the exact consent text the resident agreed to, the IP address it came from, and the version of the language displayed. That is.

3. Honor opt-outs immediately

When a resident replies STOP, STOP-ALL, UNSUBSCRIBE, CANCEL, END, or QUIT, every major SMS platform automatically suppresses future sends. But the legal bar is higher than that. You must:

  • Suppress the number across every messaging program from your community (announcements, reminders, violations, polls)
  • Send exactly one confirmation reply ("You have been unsubscribed from Maple Hills HOA messages") and no more
  • Treat any plain-English opt-out request the same way ("please stop texting me," "remove me," "I don't want these"). Do not require the magic word STOP.
  • Keep the opt-out record forever: re-adding a number after opt-out without a fresh consent is itself a TCPA violation

4. Identify the sender, every time

The CTIA Messaging Principles require sender identification on the first message of any new conversation. Practically, that means:

  • First broadcast of the year: "Maple Hills HOA: pool closed today for repairs. Reply STOP to unsubscribe."
  • New resident's first message: same identification, same opt-out reminder
  • Follow-up messages in the same thread: identification optional but never harmful

The emergency exemption (and its limits)

The TCPA carves out a narrow exception for "calls made for emergency purposes": life-safety messages where waiting for consent would cause harm. Examples: gas leak in Building C evacuate now, boil-water advisory, severe weather shelter-in-place. Counter-examples: meeting reminder, dues delinquency notice, "the pool will close at 5 PM today."

Use the emergency exemption sparingly. Every emergency message should be logged with: the nature of the emergency, who authorized the send, the time, and a copy of the message. If a board uses "emergency" to send routine reminders, the entire defense collapses.

What happens when you get sued

TCPA litigation is a cottage industry. Plaintiffs' attorneys actively monitor SMS traffic for non-compliant patterns. A typical HOA case looks like this:

  1. Resident receives an HOA text. They claim they never opted in.
  2. They file a putative class action covering all residents who received the same message.
  3. Discovery requests every consent record and the technical configuration of your messaging system.
  4. If consent records are sloppy or missing, the case settles for $50,000–$300,000+ depending on the message volume.
  5. If consent records are clean (version-controlled, timestamped, IP-logged), the case is dismissed at the motion-to-dismiss stage for a few thousand dollars in legal fees.

Practical compliance checklist

  1. Use a platform that defaults to sms_consent_status = "not_requested" until consent is captured. No "consent assumed" toggles.
  2. Require a fresh opt-in for every imported phone number, even from a previous management company that "always had consent."
  3. Display a clear consent statement before any portal opt-in. Version the language and store the version with each consent record.
  4. Send the first broadcast of the year with sender identification and a STOP reminder. Save it as a template.
  5. Suspend any number that opts out, immediately, across all programs. Do not re-add without a new consent action.
  6. Train new board members on consent before giving them broadcast permissions.
  7. Review consent logs at the annual meeting. The treasurer reviews finances; the secretary should review consent.
  8. Retain consent records for five years minimum, indefinitely if storage is cheap.

How TextHOA handles compliance for you

A platform built for HOAs handles the TCPA scaffolding automatically:

  • Consent log per member, append-only, with IP and language version baked in
  • Default sms_consent_status of "not_requested": opt-in is a deliberate action, not an assumption
  • STOP / START / HELP keywords processed natively, with audit entries
  • A2P 10DLC registration handled by the platform, including the brand and campaign vetting carriers require
  • Sender identification injected into the first message of any new thread
  • Annual consent review prompts so the board does not forget

You still own the policy, the consent language, and the decision about who to add to the system. The platform makes sure the underlying records are bulletproof, which, when a TCPA case lands on your desk, is the only thing that actually matters.

Compliance that runs on autopilot

TextHOA logs every consent, opt-out, and broadcast automatically. Audit-ready records, no spreadsheets, no surprises.

#TCPA#Compliance#Consent#HOA legal

FAQ

Frequently asked questions

Quick answers to the questions HOA boards ask most about this topic.

Does the TCPA apply to HOAs sending purely informational messages?

Yes. The TCPA applies to any automated or prerecorded message sent to a wireless number, regardless of whether the content is "marketing" or "informational." There is a narrow defense for informational messages where oral consent may suffice, but because oral consent is hard to prove later, the safe practice is to capture written consent for every recipient.

What counts as "express written consent" under the TCPA?

A clear statement, signed electronically or on paper, that authorizes the HOA to send messages to a specific phone number. The statement must identify the sender, describe the kinds of messages, state that consent is not a condition of membership, include opt-out language ("Reply STOP"), and disclose that message and data rates may apply.

How long do I need to keep consent records?

At least five years. The TCPA statute of limitations is four years, so five gives you a one-year buffer. Many HOAs retain consent logs indefinitely because the storage cost is trivial and the record is the only thing that matters in a TCPA dispute.

Can I rely on consent the previous management company captured?

No, unless you have the actual consent records, timestamped, with the consent language version, and ideally with IP or signature evidence. "We assume they consented because the previous company was texting them" is not a defense. The safe move is to re-opt-in every imported number from scratch.

What happens when a resident replies STOP?

Every reputable platform suppresses future sends to that number automatically and sends one confirmation reply ("You have been unsubscribed"). Your obligation is to honor the opt-out across every program (announcements, reminders, violations, polls), keep the opt-out record indefinitely, and never re-add the number without a fresh, deliberate consent action.

Are emergency alerts exempt from TCPA?

Genuine emergencies, life-safety messages where waiting for consent would cause harm (boil-water advisories, gas leaks, severe weather shelter-in-place), fall under a narrow TCPA exception. Routine reminders do not. Use the exemption sparingly, log every emergency send with the nature of the emergency, who authorized it, and the message content. Boards that abuse the exemption lose the defense entirely.

What are the penalties for a TCPA violation?

Statutory damages are $500 per unauthorized message, trebled to $1,500 if the violation is "knowing or willful." There is no harm requirement. A single un-consented text is a complete cause of action. Plaintiff attorneys frequently pursue these as class actions, which is why a single missed consent record can spiral into a six-figure settlement.

Have a question we did not cover? Get in touch.

Try TextHOA free

Set up your community, capture consent, send your first SMS broadcast — all in under an hour.